Search Results (44266 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-42485 1 Galaxyweblinks 1 Gallery With Thumbnail Slider 2025-01-10 5.4 Medium
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Galaxy Weblinks Gallery with thumbnail slider plugin <= 6.0 versions.
CVE-2022-41785 1 Robogallery 1 Gallery Images Ape 2025-01-10 5.4 Medium
Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Galleryape Gallery Images Ape plugin <= 2.2.8 versions.
CVE-2022-45843 1 Nextendweb 1 Smart Slider 3 2025-01-10 5.4 Medium
Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Nextend Smart Slider 3 plugin <= 3.5.1.9 versions.
CVE-2022-44742 1 Community Events Project 1 Community Events 2025-01-10 4.8 Medium
Auth. (admin+) Stored Cross-Site Scripting vulnerability in Yannick Lefebvre Community Events plugin <= 1.4.8 versions.
CVE-2023-28422 1 Mage-people 1 Event Manager And Tickets Selling For Woocommerce 2025-01-10 5.9 Medium
Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6. versions.
CVE-2022-47431 1 Tussendoor 1 Open Rdw Kenteken Voertuiginformatie 2025-01-10 7.1 High
Reflected Cross-Site Scripting (XSS) vulnerability in Tussendoor internet & marketing Open RDW kenteken voertuiginformatie plugin <= 2.0.14 versions.
CVE-2023-22716 1 Oopspam 1 Oopspam Anti-spam 2025-01-10 5.9 Medium
Auth. (admin+) Cross-Site Scripting vulnerability in OOPSpam OOPSpam Anti-Spam plugin <= 1.1.35 versions.
CVE-2023-22712 1 Templatesnext 1 Templatesnext Toolkit 2025-01-10 6.5 Medium
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TemplatesNext TemplatesNext ToolKit plugin <= 3.2.7 versions.
CVE-2023-23650 1 Mainwp 1 Code Snippets Extension 2025-01-10 6.5 Medium
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in MainWP MainWP Code Snippets Extension plugin <= 4.0.2 versions.
CVE-2023-23864 1 Very Simple Google Maps Project 1 Very Simple Google Maps 2025-01-10 6.5 Medium
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Michael Aronoff Very Simple Google Maps plugin <= 2.8.4 versions.
CVE-2022-47589 1 Thisfunctional 1 Ctt Expresso Para Woocommerce 2025-01-10 5.9 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in this.Functional CTT Expresso para WooCommerce plugin <= 3.2.11 versions.
CVE-2022-47173 1 Advancedformintegration 1 Advanced Form Integration 2025-01-10 5.9 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nasirahmed Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration plugin <= 1.62.0 versions.
CVE-2023-25992 1 Cminds 1 Cm Answers 2025-01-10 5.9 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeMindsSolutions CM Answers plugin <= 3.1.9 versions.
CVE-2022-47146 1 Contempothemes 1 Real Estate 7 2025-01-10 7.1 High
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 versions.
CVE-2022-45825 1 Liquidweb 1 Wpcomplete 2025-01-10 7.1 High
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in iThemes WPComplete plugin <= 2.9.2 versions.
CVE-2022-45831 1 Oxilab 1 Image Hover Effects For Elementor With Lightbox And Flipbox 2025-01-10 7.1 High
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in biplob018 Image Hover Effects for Elementor with Lightbox and Flipbox plugin <= 2.8 versions.
CVE-2023-3026 1 Diagrams 1 Drawio 2025-01-10 6.1 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 21.2.8.
CVE-2022-45938 1 Xfinity 1 Comcast Defined Technologies Microeisbss 2025-01-10 8 High
An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code Execution and privilege escalation..
CVE-2022-46863 1 Fullworksplugins 1 Quick Event Manager 2025-01-10 5.9 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.6.4 versions.
CVE-2022-47170 1 Unlimited-elements 1 Unlimited Elements For Elementor 2025-01-10 5.9 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.48 versions.