• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2022-0765

February 23, 2023 by

The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source translation strings before outputting them in the editor in the plugin admin panel, allowing any user with access to the plugin (Translator and Administrator by default) to add arbitrary javascript payloads to the source strings leading to a stored cross-site scripting (XSS) vulnerability.

CVE-2022-0772

February 23, 2023 by

Cross-site Scripting (XSS) – Stored in GitHub repository librenms/librenms prior to 22.2.2.

CVE-2022-0776

February 23, 2023 by

Cross-site Scripting (XSS) – DOM in GitHub repository hakimel/reveal.js prior to 4.3.0.

CVE-2022-0780

February 23, 2023 by

The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter

CVE-2022-0801

February 23, 2023 by

Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass XSS preventions via a crafted HTML page. (Chrome security severity: Medium)

CVE-2022-0674

February 23, 2023 by

The Kunze Law WordPress plugin before 2.1 does not escape its ‘E-Mail Error “From” Address’ settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 2148
  • Go to page 2149
  • Go to page 2150
  • Go to page 2151
  • Go to page 2152
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE