Vulnerabilities (CVE)

Filtered by CWE-79
Total 47482 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-3442 1 Crealogix 1 Ebics Server 2026-06-17 N/A 3.5 LOW
A vulnerability was found in Crealogix EBICS 7.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /ebics-server/ebics.aspx. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.1 is able to address this issue. It is recommended to upgrade the affected component. VDB-210374 is the identifier assigned to this vulnerability.
CVE-2022-3441 1 Rockcontent 1 Rock Convert 2026-06-17 N/A 4.8 MEDIUM
The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-3440 1 Rockcontent 1 Rock Convert 2026-06-17 N/A 6.1 MEDIUM
The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attribute when a specific widget is present on a page, leading to a Reflected Cross-Site Scripting
CVE-2022-3434 1 Web-based Student Clearance System Project 1 Web-based Student Clearance System 2026-06-17 N/A 3.5 LOW
A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been rated as problematic. Affected by this issue is the function prepare of the file /Admin/add-student.php. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210356.
CVE-2022-3420 1 Official Integration For Billingo Project 1 Official Integration For Billingo 2026-06-17 N/A 4.8 MEDIUM
The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow high privilege users with a role as low as Shop Manager to perform Stored Cross-Site Scripting attacks.
CVE-2022-3415 1 Bluecoral 1 Chat Bubble 2026-06-17 N/A 6.1 MEDIUM
The Chat Bubble WordPress plugin before 2.3 does not sanitise and escape some contact parameters, which could allow unauthenticated attackers to set Stored Cross-Site Scripting payloads in them, which will trigger when an admin view the related contact message
CVE-2022-3408 1 Redlettuce 1 Wp Word Count 2026-06-17 N/A 4.8 MEDIUM
The WP Word Count WordPress plugin through 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
CVE-2022-3402 1 Facetwp 1 Log Http Requests 2026-06-17 N/A 6.1 MEDIUM
The Log HTTP Requests plugin for WordPress is vulnerable to Stored Cross-Site Scripting via logged HTTP requests in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers who can trick a site's administrator into performing an action like clicking on a link, or an authenticated user with access to a page that sends a request using user-supplied data via the server, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2022-3399 2026-06-17 N/A 4.4 MEDIUM
The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cookie_notice_options[refuse_code_head]' parameter in versions up to, and including, 2.4.17.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative privileges and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the injected /wp-admin/admin.php?page=cookie-notice page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
CVE-2022-3392 1 Wp Humans.txt Project 1 Wp Humans.txt 2026-06-17 N/A 4.8 MEDIUM
The WP Humans.txt WordPress plugin through 1.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-3391 1 Retain 1 Retain Live Chat 2026-06-17 N/A 4.8 MEDIUM
The Retain Live Chat WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-3355 1 Inventree Project 1 Inventree 2026-06-17 N/A 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3.
CVE-2022-3350 1 Tech-banker 1 Contact Bank 2026-06-17 N/A 4.8 MEDIUM
The Contact Bank WordPress plugin through 3.0.30 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2022-3339 1 Mcafee 1 Epolicy Orchestrator 2026-06-17 N/A 5.4 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 Update 14 allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's session by convincing the authenticated ePO administrator to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO.
CVE-2022-3265 1 Gitlab 1 Gitlab 2026-06-17 N/A 7.3 HIGH
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side.
CVE-2022-3255 1 Pimcore 1 Pimcore 2026-06-17 N/A 4.8 MEDIUM
If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user. Amongst other things, the attacker can: Perform any action within the application that the user can perform. View any information that the user is able to view. Modify any information that the user is able to modify. Initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user.
CVE-2022-3245 1 Microweber 1 Microweber 2026-06-17 N/A 6.1 MEDIUM
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.
CVE-2022-3242 1 Microweber 1 Microweber 2026-06-17 N/A 6.1 MEDIUM
Code Injection in GitHub repository microweber/microweber prior to 1.3.2.
CVE-2022-3237 1 Wpexperts 1 Wp Contact Slider 2026-06-17 N/A 4.8 MEDIUM
The WP Contact Slider WordPress plugin before 2.4.8 does not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-3231 1 Librenms 1 Librenms 2026-06-17 N/A 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0.