Total
30469 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-5661 | 1 Responsive Coming Soon Page Project | 1 Responsive Coming Soon Page | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php logo_width parameter. | |||||
CVE-2018-5660 | 1 Responsive Coming Soon Page Project | 1 Responsive Coming Soon Page | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php coming-soon_sub_title parameter. | |||||
CVE-2018-5659 | 1 Responsive Coming Soon Page Project | 1 Responsive Coming Soon Page | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php coming-soon_title parameter. | |||||
CVE-2018-5657 | 1 Responsive Coming Soon Page Project | 1 Responsive Coming Soon Page | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php counter_title_icon parameter. | |||||
CVE-2018-5655 | 1 Weblizar | 1 Pinterest-feeds | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php security parameter. | |||||
CVE-2018-5654 | 1 Weblizar | 1 Pinterest-feeds | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php PFFREE_Access_Token parameter. | |||||
CVE-2018-5653 | 1 Weblizar | 1 Pinterest-feeds | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php weblizar_pffree_settings_save_get-users parameter. | |||||
CVE-2018-5652 | 1 Dark Mode Project | 1 Dark Mode | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in the dark-mode plugin 1.6 for WordPress. XSS exists via the wp-admin/profile.php dark_mode_end parameter. | |||||
CVE-2018-5651 | 1 Dark Mode Project | 1 Dark Mode | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in the dark-mode plugin 1.6 for WordPress. XSS exists via the wp-admin/profile.php dark_mode_start parameter. | |||||
CVE-2018-5550 | 1 Epson | 1 Airprint | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allow untrusted users on the network to hijack a session cookie or perform other reflected XSS attacks on a currently logged-on user. | |||||
CVE-2018-5479 | 1 Foxsash | 1 Imghosting | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its search engine via the search parameter to the default URI. Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an infected URL, code will be executed. | |||||
CVE-2018-5376 | 1 Discuz | 1 Discuzx | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_upload.php op parameter. | |||||
CVE-2018-5375 | 1 Discuz | 1 Discuzx | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_space.php appid parameter in a delete action. | |||||
CVE-2018-5370 | 1 Bizlogicdev | 1 Xnami | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
BizLogic xnami 1.0 has XSS via the comment parameter in an addComment action to the /media/ajax URI. | |||||
CVE-2018-5369 | 1 Srbtranslatin Project | 1 Srbtranslatin | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The SrbTransLatin plugin 1.46 for WordPress has XSS via an srbtranslatoptions action to wp-admin/options-general.php with a lang_identificator parameter. | |||||
CVE-2018-5367 | 1 Wpglobus | 1 Wpglobus | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][post] parameter to wp-admin/options.php. | |||||
CVE-2018-5366 | 1 Wpglobus | 1 Wpglobus | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[more_languages] parameter to wp-admin/options.php. | |||||
CVE-2018-5365 | 1 Wpglobus | 1 Wpglobus | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[selector_wp_list_pages][show_selector] parameter to wp-admin/options.php. | |||||
CVE-2018-5364 | 1 Wpglobus | 1 Wpglobus | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[browser_redirect][redirect_by_language] parameter to wp-admin/options.php. | |||||
CVE-2018-5363 | 1 Wpglobus | 1 Wpglobus | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[enabled_languages][en] or wpglobus_option[enabled_languages][fr] (or any other language) parameter to wp-admin/options.php. |