Latest CVE Feed
-
5.4
MEDIUMCVE-2024-3763
A vulnerability was found in Emlog Pro 2.2.10. It has been rated as problematic. This issue affects some unknown processing of the file /admin/tag.php of the component Post Tag Handler. The manipulation leads to cross site scripting. The attack may be ini... Read more
- Published: Apr. 14, 2024
- Modified: Mar. 05, 2025
-
5.4
MEDIUMCVE-2024-32452
Cross-Site Request Forgery (CSRF) vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19. ... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-32093
Cross-Site Request Forgery (CSRF) vulnerability in Nose Graze Novelist.This issue affects Novelist: from n/a through 1.2.2. ... Read more
Affected Products : novelist- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-31434
Cross-Site Request Forgery (CSRF) vulnerability in Stefano Lissa & The Newsletter Team Newsletter.This issue affects Newsletter: from n/a through 8.0.6. ... Read more
Affected Products : newsletter- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-22540
Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive information via crafted payload to Category name component.... Read more
Affected Products : codoforum- Published: Apr. 15, 2024
- Modified: Apr. 18, 2025
-
5.4
MEDIUMCVE-2024-32506
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. ... Read more
Affected Products : radio_player- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-32338
A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the PAGE TITLE parameter under the Current Page module.... Read more
Affected Products : wondercms- Published: Apr. 17, 2024
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2025-4292
A vulnerability has been found in MRCMS 3.1.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/user/edit.do of the component Edit User Page. The manipulation of the argument Username leads to cro... Read more
Affected Products : mrcms- Published: May. 05, 2025
- Modified: Jun. 17, 2025
-
5.4
MEDIUMCVE-2024-32142
Missing Authorization vulnerability in Ovic Team Ovic Responsive WPBakery.This issue affects Ovic Responsive WPBakery: from n/a through 1.3.0. ... Read more
Affected Products :- Published: Apr. 18, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-27752
Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword field in the settings function.... Read more
Affected Products : csz_cms- Published: Apr. 19, 2024
- Modified: May. 21, 2025
-
5.4
MEDIUMCVE-2024-1730
The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via urls in link fields, images... Read more
Affected Products : prime_slider- Published: Apr. 20, 2024
- Modified: Feb. 05, 2025
-
5.4
MEDIUMCVE-2024-22856
A SQL injection vulnerability via the Save Favorite Search function in Axefinance Axe Credit Portal >= v.3.0 allows authenticated attackers to execute unintended queries and disclose sensitive information from DB tables via crafted requests.... Read more
Affected Products : caldera- Published: Apr. 22, 2024
- Modified: Nov. 22, 2024
-
5.4
MEDIUMCVE-2025-4293
A vulnerability was found in MRCMS 3.1.3 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/group/edit.do of the component Group Edit Page. The manipulation leads to cross site scripting. The attack may ... Read more
Affected Products : mrcms- Published: May. 05, 2025
- Modified: Jun. 17, 2025
-
5.4
MEDIUMCVE-2024-4174
Cross-Site Scripting (XSS) vulnerability in Hyperion Web Server affecting version 2.0.15. This vulnerability could allow an attacker to execute malicious Javascript code on the client by injecting that code into the URL.... Read more
Affected Products :- Published: Apr. 25, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-4304
A Cross-Site Scripting XSS vulnerability has been detected on GT3 Soluciones SWAL. This vulnerability consists in a reflected XSS in the Titular parameter inside Gestion 'Documental > Seguimiento de Expedientes > Alta de Expedientes'.... Read more
Affected Products :- Published: Apr. 29, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-33102
A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the code parameter.... Read more
Affected Products : thinksaas- Published: Apr. 30, 2024
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2024-33307
SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" parameter in Create User.... Read more
Affected Products : laboratory_management_system- Published: May. 01, 2024
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2024-4203
The Premium Addons Pro for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maps widget in all versions up to, and including, 4.10.30 due to insufficient input sanitization and output escaping on user supplied attributes... Read more
Affected Products : premium_addons_for_elementor- Published: May. 02, 2024
- Modified: Jan. 15, 2025
-
5.4
MEDIUMCVE-2023-7065
The Stop Spammers Security | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2024.4. This is due to missing or incorrect nonce validation on the sfs_process AJAX acti... Read more
Affected Products :- Published: May. 04, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-33829
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=updateWebCache.... Read more
- Published: May. 06, 2024
- Modified: Apr. 15, 2025