|
197801
|
6.1 |
MEDIUM
Network
|
cozyvision
|
sms_alert_order_notifications
|
The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.
|
-
|
CVE-2021-24588
|
2024-11-21 14:53 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197802
|
5.4 |
MEDIUM
Network
|
addtoany
|
addtoany_share_buttons
|
The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting it in frontend pages, allowing high privilege users such as admin to perform Cro…
|
-
|
CVE-2021-24568
|
2024-11-21 14:53 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197803
|
5.4 |
MEDIUM
Network
|
trumani
|
stop_spammers
|
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scri…
|
-
|
CVE-2021-24517
|
2024-11-21 14:53 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197804
|
5.4 |
MEDIUM
Network
|
web-settler
|
form_builder
|
The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting …
|
-
|
CVE-2021-24513
|
2024-11-21 14:53 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197805
|
6.1 |
MEDIUM
Network
|
gambit
|
titan_framework
|
The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected …
|
CWE-79
Cross-site Scripting
|
CVE-2021-24435
|
2024-11-21 14:53 |
2021-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197806
|
5.4 |
MEDIUM
Network
|
simplygallery
|
simply_gallery_blocks_with_lightbox
|
A stored cross-site scripting vulnerability has been discovered in : Simply Gallery Blocks with Lightbox (Version – 2.2.0 & below). The vulnerability exists in the Lightbox functionality where a user…
|
-
|
CVE-2021-24667
|
2024-11-21 14:53 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197807
|
5.4 |
MEDIUM
Network
|
tipsandtricks-hq
|
wp_video_lightbox
|
The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks
|
CWE-79
Cross-site Scripting
|
CVE-2021-24665
|
2024-11-21 14:53 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197808
|
5.4 |
MEDIUM
Network
|
business_hours_indicator_project
|
business_hours_indicator
|
The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting when outputting it in the backend and frontend, leading to an Authenticated Sto…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24593
|
2024-11-21 14:53 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197809
|
4.8 |
MEDIUM
Network
|
yoohooplugins
|
sitewide_notice
|
The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in frontend pages, allowing high privilege users to perform Cross-Site Scripting attac…
|
CWE-79
Cross-site Scripting
|
CVE-2021-24592
|
2024-11-21 14:53 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197810
|
8.8 |
HIGH
Network
|
blue-admin_project
|
blue-admin
|
The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plu…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2021-24581
|
2024-11-21 14:53 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|