Cross-Site Scripting

XSS vulnerabilities allowing script injection
59 CVEs tagged.

CVE-2022-50797 6.4

The Stripe Green Downloads WordPress plugin version 2.03 contains a persistent cross-site scripting (XSS) vulnerability in button label fields. Attack...

Feb 1, 2026
CVE-2021-47911 5.4

Affiliate Pro 1.7 contains reflected cross-site scripting vulnerabilities in index module input fields (fullname, username, email). Attackers can inje...

Feb 1, 2026
CVE-2021-47912 6.4

PHP Melody 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and user import files. Attackers can injec...

Feb 1, 2026
CVE-2021-47913 6.4

PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor's WYSIWYG component. Privileged users can inject malicious...

Feb 1, 2026
CVE-2021-47914 6.4

PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that allows remote attackers to inje...

Feb 1, 2026
CVE-2021-47856 6.4

Easy Cart Shopping Cart 2021 contains a non-persistent cross-site scripting vulnerability in the search module's keyword parameter. Remote attackers c...

Feb 1, 2026
CVE-2021-47885 6.4

Multiple payment terminal versions contain non-persistent cross-site scripting (XSS) vulnerabilities in billing and payment information input fields. ...

Feb 1, 2026
CVE-2021-47908 6.4

Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows attackers to inject malicious scri...

Feb 1, 2026
CVE-2024-35280 5.4

This vulnerability allows attackers to perform reflected cross-site scripting (XSS) attacks against FortiDeceptor recovery endpoints. Attackers can in...

Jan 15, 2025