Skip to main content

CWE archive

CWE-80 CVEs

Programmatic archive

561 CVEs tagged with CWE-8018 Critical, 86 High, 375 Medium, 80 Low, 2 Unrated.

CVE-2024-47139

Published Oct 16, 2024

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run Java…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-32193

Published Oct 16, 2024

A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in Norman's public API endpoint can be exploited. This can lead to an attacker exploiting…

CVSS 8.3 · High

CVE-2023-32192

Published Oct 16, 2024

A vulnerability has been identified in which unauthenticated cross-site scripting (XSS) in the API Server's public API endpoint can be exploited, allowing an attacker to execute…

CVSS 8.3 · High

CVE-2024-47815

Published Oct 9, 2024

IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a variety of Cross-site Scripting issues, though all of them req…

CVSS 6.0 · Medium

CVE-2024-47812

Published Oct 9, 2024

ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface strings of a wiki (typically administrators and interface adm…

CVSS 6.0 · Medium

CVE-2024-47782

Published Oct 7, 2024

WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. Special:WikiDiscover is a special page that lists all wikis on the wiki farm. Howeve…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38039

Published Oct 4, 2024

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clic…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47765

Published Oct 4, 2024

Minecraft MOTD Parser is a PHP library to parse minecraft server motd. The HtmlGenerator class is subject to potential cross-site scripting (XSS) attack through a parsed malformed…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47612

Published Oct 2, 2024

DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifically, (datadump-table-column-queued), (datadump-table-column…

CVSS 3.5 · Low

CVE-2024-8981

Published Oct 1, 2024

The Broken Link Checker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg in /app/admin-notices/features/class-view.php without…

CVSS 7.1 · High

CVE-2024-47536

Published Sep 30, 2024

Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselve…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8872

Published Sep 26, 2024

The Store Hours for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8680

Published Sep 21, 2024

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.9.16 due to insuffi…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27915

Published Sep 17, 2024

Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2010

Published Sep 12, 2024

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in TE Informatics V5 allows Reflected XSS. This issue affects V5: before 6.2.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45406

Published Sep 9, 2024

Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38859

Published Aug 26, 2024

XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users to execute arbitrary scripts…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8145

Published Aug 25, 2024

A vulnerability, which was classified as problematic, has been found in ClassCMS 4.8. Affected by this issue is some unknown functionality of the file /index.php/admin of the comp…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7629

Published Aug 21, 2024

The Responsive video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's video settings function in all versions up to, and including, 1.0 due to in…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41947

Published Jul 31, 2024

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently edi…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-41810

Published Jul 29, 2024

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If appl…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 561 CVEsPage 12 of 23