Latest CVE Feed
-
5.4
MEDIUMCVE-2023-33394
skycaiji v2.5.4 is vulnerable to Cross Site Scripting (XSS). Attackers can achieve backend XSS by deploying malicious JSON data.... Read more
Affected Products : skycaiji- EPSS Score: %0.08
- Published: May. 26, 2023
- Modified: Jan. 15, 2025
-
5.4
MEDIUMCVE-2024-56923
Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is achieved by injecting a malicious paylo... Read more
Affected Products : silverpeas- Published: Jan. 22, 2025
- Modified: May. 28, 2025
-
5.4
MEDIUMCVE-2023-32340
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credent... Read more
Affected Products : sterling_b2b_integrator- Published: Jan. 23, 2025
- Modified: Mar. 04, 2025
-
5.4
MEDIUMCVE-2022-36244
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 suffers from Multiple Stored Cross-Site Scripting (XSS) vulnerabilities via Shop Beat Control Panel found at www.shopbeat.co.za controlpanel.shopbeat.co.za.... Read more
Affected Products : shop_beat_media_player- EPSS Score: %0.08
- Published: May. 30, 2023
- Modified: Jan. 13, 2025
-
5.4
MEDIUMCVE-2025-24712
Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Radius Blocks allows Cross Site Request Forgery. This issue affects Radius Blocks: from n/a through 2.1.2.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
5.4
MEDIUMCVE-2025-24715
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Counter Box allows Cross Site Request Forgery. This issue affects Counter Box: from n/a through 2.0.5.... Read more
Affected Products : counter_box- Published: Jan. 24, 2025
- Modified: Jun. 09, 2025
-
5.4
MEDIUMCVE-2025-24720
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Sticky Buttons allows Cross Site Request Forgery. This issue affects Sticky Buttons: from n/a through 4.1.1.... Read more
Affected Products : sticky_buttons- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
5.4
MEDIUMCVE-2025-24724
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite allows Cross Site Request Forgery. This issue affects Side Menu Lite: from n/a through 5.3.1.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
5.4
MEDIUMCVE-2024-35112
IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.... Read more
Affected Products : control_center- Published: Jan. 25, 2025
- Modified: Mar. 04, 2025
-
5.4
MEDIUMCVE-2023-3035
A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Schedule Handler. The manipulation of the argument descriptio... Read more
Affected Products : pythagorean_oa_office_system- EPSS Score: %0.07
- Published: Jun. 01, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-24533
Cross-Site Request Forgery (CSRF) vulnerability in MetaSlider Responsive Slider by MetaSlider allows Cross Site Request Forgery. This issue affects Responsive Slider by MetaSlider: from n/a through 3.92.0.... Read more
Affected Products : slider\,_gallery\,_and_carousel- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
5.4
MEDIUMCVE-2025-24538
Cross-Site Request Forgery (CSRF) vulnerability in slaFFik BuddyPress Groups Extras allows Cross Site Request Forgery. This issue affects BuddyPress Groups Extras: from n/a through 3.6.10.... Read more
Affected Products :- Published: Jan. 27, 2025
- Modified: Jan. 27, 2025
-
5.4
MEDIUMCVE-2025-22917
A reflected cross-site scripting (XSS) vulnerability in Audemium ERP <=0.9.0 allows remote attackers to execute an arbitrary JavaScript payload in the web browser of a user by including a malicious payload into the 'type' parameter of list.php.... Read more
Affected Products :- Published: Jan. 28, 2025
- Modified: Jan. 29, 2025
-
5.4
MEDIUMCVE-2024-57438
Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.... Read more
Affected Products : ruoyi- Published: Jan. 29, 2025
- Modified: May. 14, 2025
-
5.4
MEDIUMCVE-2019-25143
The GDPR Cookie Compliance plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the gdpr_cookie_compliance_reset_settings AJAX action in versions up to, and including, 4.0.2. This makes it possible for authentica... Read more
Affected Products : gdpr_cookie_compliance- EPSS Score: %0.03
- Published: Jun. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-3143
A vulnerability classified as problematic has been found in SourceCodester Online Discussion Forum Site 1.0. Affected is an unknown function of the file admin\posts\manage_post.php. The manipulation of the argument content leads to cross site scripting. I... Read more
- EPSS Score: %0.07
- Published: Jun. 07, 2023
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2024-10867
The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.9 due to insufficient input sanitization a... Read more
Affected Products : borderless- Published: Jan. 31, 2025
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2024-13101
The WP MediaTagger WordPress plugin through 4.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform... Read more
Affected Products : wp_mediatagger- Published: Jan. 31, 2025
- Modified: May. 11, 2025
-
5.4
MEDIUMCVE-2023-2031
The Locatoraid Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping on user supplied attributes. T... Read more
- EPSS Score: %0.09
- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-2414
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_settings_callback function in versions up to, and including, 4.4.6.... Read more
- EPSS Score: %0.06
- Published: Jun. 09, 2023
- Modified: Mar. 20, 2025