Latest CVE Feed
-
5.4
MEDIUMCVE-2021-42085
An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.... Read more
Affected Products : zammad- EPSS Score: %0.50
- Published: Oct. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-41918
webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against the platform users and administrators. Th... Read more
Affected Products : webtareas- EPSS Score: %0.32
- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24576
The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordion.... Read more
Affected Products : easy_accordion- EPSS Score: %0.18
- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40888
Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in returnFilesIds() function. A low privilege user can call this function through process.php file and execute scripting code.... Read more
Affected Products : projectsend- EPSS Score: %0.21
- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20797
Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain the information stored in the product. This issue occurs only when using Mozilla Firefox.... Read more
- EPSS Score: %0.21
- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20800
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.... Read more
- EPSS Score: %0.21
- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20805
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.7 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.... Read more
- EPSS Score: %0.21
- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36387
In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a specially crafted HTTP POST request to the page "ActivityStreamAjax.i4".... Read more
Affected Products : yellowfin- EPSS Score: %3.74
- Published: Oct. 14, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-6613
A vulnerability classified as problematic was found in PHPGurukul Hospital Management System 4.0. Affected by this vulnerability is an unknown functionality of the file /doctor/manage-patient.php. The manipulation of the argument Name leads to cross site ... Read more
Affected Products : hospital_management_system hospital_management_system hospital_management_system- Published: Jun. 25, 2025
- Modified: Jul. 02, 2025
-
5.4
MEDIUMCVE-2021-24412
The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered i... Read more
Affected Products : html5_audio_player- EPSS Score: %0.18
- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24413
The Easy Twitter Feed WordPress plugin before 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the ... Read more
Affected Products : easy_twitter_feed- EPSS Score: %0.18
- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24416
The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the pa... Read more
Affected Products : streamcast_radio_player- EPSS Score: %0.18
- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24732
The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.10 does not escape the class attribute of its shortcode before outputting it back in an attribute, which could allow users with a role as low as Contributor to perform Stored C... Read more
Affected Products : dearflip- EPSS Score: %0.18
- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-5998
Cross-site scripting (XSS) vulnerability in InterSect Alliance SNARE Epilog for UNIX version 1.5 allows remote authenticated users to inject arbitrary web script or HTML via the str_log_name parameter in a "Web Admin Portal > Log Configuration > Add" acti... Read more
Affected Products : snare_epilog- EPSS Score: %0.15
- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2021-29912
IBM Security Risk Manager on CP4S 1.7.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within... Read more
- EPSS Score: %0.11
- Published: Oct. 19, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-23039
Folder Lock v3.4.5 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Create Folder function under the 'create' module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload as a... Read more
Affected Products : folder_lock- EPSS Score: %0.28
- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-28968
Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the username... Read more
- EPSS Score: %0.21
- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-36489
Dropouts Technologies LLP Air Share v1.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the devicename parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the devicename... Read more
Affected Products : air_share- EPSS Score: %0.21
- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-36491
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tags_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.... Read more
Affected Products : dedecms- EPSS Score: %0.18
- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-36492
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component select_media.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.... Read more
Affected Products : dedecms- EPSS Score: %0.18
- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024