Show filters
50 Total Results
Displaying 1-10 of 50
Sort by:
Attacker Value
Unknown

CVE-2024-27136

Disclosure Date: June 24, 2024 (last updated October 18, 2024)
XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later.
Attacker Value
Unknown

CVE-2024-1257

Disclosure Date: February 06, 2024 (last updated February 10, 2024)
A vulnerability was found in Jspxcms 10.2.0. It has been classified as problematic. Affected is an unknown function of the file /ext/collect/find_text.do. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252996.
Attacker Value
Unknown

CVE-2024-1256

Disclosure Date: February 06, 2024 (last updated February 10, 2024)
A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. This issue affects some unknown processing of the file /ext/collect/filter_text.do. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252995.
Attacker Value
Unknown

CVE-2024-1200

Disclosure Date: February 03, 2024 (last updated February 13, 2024)
A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /template/1/default/. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252698 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-0721

Disclosure Date: January 19, 2024 (last updated January 26, 2024)
A vulnerability has been found in Jspxcms 10.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Survey Label Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-251545 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-0599

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
A vulnerability was found in Jspxcms 10.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file src\main\java\com\jspxcms\core\web\back\InfoController.java of the component Document Management Page. The manipulation of the argument title leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250837 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-46911

Disclosure Date: November 01, 2023 (last updated November 09, 2023)
There is a Cross Site Scripting (XSS) vulnerability in the choose_style_tree.do interface of Jspxcms v10.2.0 backend.
Attacker Value
Unknown

CVE-2022-46907

Disclosure Date: May 25, 2023 (last updated February 14, 2025)
A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.0 or later.
Attacker Value
Unknown

CVE-2023-28151

Disclosure Date: March 24, 2023 (last updated October 08, 2023)
An issue was discovered in Independentsoft JSpreadsheet before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX file.
Attacker Value
Unknown

CVE-2022-48115

Disclosure Date: February 17, 2023 (last updated October 08, 2023)
The dropdown menu in jspreadsheet before v4.6.0 was discovered to be vulnerable to cross-site scripting (XSS).