CVE-2024-53384

CVSS v3 Score
5.1
Medium

Vulnerability Description

A DOM Clobbering vulnerability in tsup v8.3.4 allows attackers to execute arbitrary code via a crafted script in the import.meta.url to document.currentScript in cjs_shims.js components

CVSS:5.1(Medium)

Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2.

CWE-792022
CVSS:5.1(Medium)

Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.

CWE-792023
CVSS:5.1(Medium)

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.20.

CWE-792023
CVSS:5.1(Medium)

The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scriptin...

CWE-792024
CVSS:5.1(Medium)

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Catch Themes Full frame allows Stored XSS.This issue affects Full frame: from n/a through 2...

CWE-792024
CVSS:5.1(Medium)

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Catch Themes Catch Base allows Stored XSS.This issue affects Catch Base: from n/a through 3...

CWE-792024