Skip to content
Noroxi

CWE-82 · 8 records

Improper Neutralization of Script in Attributes of IMG Tags in a Web Page

CVEs in this class

8 records

  • WordPress Contact Form by Supsystic plugin <= 1.7.28 - Remote Code Execution (RCE) vulnerability

    CriticalCVSS 9.1No exploitEPSS 1%

    supsystic · contact form by supsysticOct 16, 2024

  • WordPress Popup by Supsystic plugin <= 1.10.29 - Remote Code Execution (RCE) vulnerability

    CriticalCVSS 9.1No exploitEPSS 1%

    supsystic · popupNov 18, 2024

  • WordPress Event Tickets with Ticket Scanner plugin <= 2.3.11 - Remote Code Execution (RCE) vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    vollstart · event tickets with ticket scannerNov 18, 2024

  • WordPress JetEngine <= 3.7.0 - Remote Code Execution (RCE) Vulnerability

    HighCVSS 8.5No exploitEPSS 0%

    crocoblock · jetengineAug 20, 2025

  • WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.121 - Remote Code Execution (RCE) vulnerability

    HighCVSS 7.2No exploitEPSS 1%

    unlimited-elements · unlimited elements for elementorOct 16, 2024

  • WordPress Podlove Podcast Publisher plugin <= 4.1.15 - Admin+ Remote Code Execution (RCE) vulnerability

    HighCVSS 7.2No exploitEPSS 1%

    podlove · podlove podcast publisherNov 14, 2024

  • Zammad: Improper neutralization of `srcset` attribute in IMG tags in Zammad

    MediumCVSS 5.3No exploitEPSS 0%

    zammad · zammad5 days ago

  • Stored XSS in Foundry Slate Query Dropdown menu

    MediumCVSS 5.4No exploitEPSS 0%

    palantir · foundry frontendJul 10, 2023

All vulnerability classes