element-plus 2.0.5 is vulnerable to Cross Site Scripting (XSS) via el-table-column.
CWE-79
CVE-2022-27105
InMailX Outlook Plugin < 3.22.0101 is vulnerable to Cross Site Scripting (XSS). InMailX Connection names are not sanitzed in the Outlook tab, which allows a local user or network administrator to execute HTML / Javascript in the Outlook of users.
CVE-2022-27107
OrangeHRM 4.10 is vulnerable to Stored XSS in the “Share Video” section under “OrangeBuzz” via the GET/POST “createVideo[linkAddress]” parameter
CVE-2022-27111
Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute it.
CVE-2022-27125
zbzcms v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the neirong parameter at /php/ajax.php.
CVE-2022-27156
Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injection.