pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
CWE-79
CVE-2021-40840
A Stored XSS issue exists in the admin/users user administration form in LiveConfig 2.12.2.
CVE-2021-4072
elgg is vulnerable to Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
CVE-2021-40721
Adobe Connect version 11.2.3 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim’s browser.
CVE-2021-4074
The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/bridge_cp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1. Due to missing authorization checks on the cc_whmcs_bridge_add_admin function, low-level authenticated users such as subscribers can exploit this vulnerability.
CVE-2021-40637
OS4ED openSIS 8.0 is affected by cross-site scripting (XSS) in EmailCheckOthers.php. An attacker can inject JavaScript code to get the user’s cookie and take over the working session of user.
