Show filters
4,854 Total Results
Displaying 31-40 of 4,854
Sort by:
Attacker Value
Very Low

CVE-2020-9371

Disclosure Date: March 04, 2020 (last updated February 21, 2025)
Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to inject arbitrary JavaScript or HTML.
Attacker Value
Low

CVE-2020-9339

Disclosure Date: February 22, 2020 (last updated February 21, 2025)
SOPlanning 1.45 allows XSS via the Name or Comment to status.php.
Attacker Value
Very High

CVE-2020-9338

Disclosure Date: February 22, 2020 (last updated February 21, 2025)
SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field.
Attacker Value
Low

CVE-2020-7208

Disclosure Date: February 13, 2020 (last updated February 21, 2025)
LinuxKI v6.0-1 and earlier is vulnerable to an XSS which is resolved in release 6.0-2.
Attacker Value
Very Low

CVE-2020-5308

Disclosure Date: January 07, 2020 (last updated February 21, 2025)
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to XSS, as demonstrated by the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName parameter in add-product.php.
Attacker Value
Unknown

CVE-2025-26973

Disclosure Date: February 22, 2025 (last updated February 23, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WarfarePlugins Social Warfare allows DOM-Based XSS. This issue affects Social Warfare: from n/a through 4.5.4.
0
Attacker Value
Unknown

CVE-2025-26774

Disclosure Date: February 22, 2025 (last updated February 23, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Solid Responsive Modal Builder for High Conversion – Easy Popups allows Reflected XSS. This issue affects Responsive Modal Builder for High Conversion – Easy Popups: from n/a through 1.5.0.
0
Attacker Value
Unknown

CVE-2025-26756

Disclosure Date: February 22, 2025 (last updated February 23, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in grimdonkey Magic the Gathering Card Tooltips allows Stored XSS. This issue affects Magic the Gathering Card Tooltips: from n/a through 3.5.0.
0
Attacker Value
Unknown

CVE-2025-0957

Disclosure Date: February 22, 2025 (last updated February 23, 2025)
The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2025-0953

Disclosure Date: February 22, 2025 (last updated February 23, 2025)
The SMTP for Sendinblue – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.