Latest CVE Feed
-
5.4
MEDIUMCVE-2022-4652
The Video Background WordPress plugin before 2.7.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perfor... Read more
Affected Products : video_background- Published: Mar. 13, 2023
- Modified: Feb. 27, 2025
-
5.4
MEDIUMCVE-2023-0219
The FluentSMTP WordPress plugin before 2.2.3 does not sanitize or escape email content, making it vulnerable to stored cross-site scripting attacks (XSS) when an administrator views the email logs. This exploit requires other plugins to enable users to se... Read more
Affected Products : fluentsmtp- Published: Mar. 13, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-6078
Partner Software's Partner Software application and Partner Web application allows an authenticated user to add notes on the 'Notes' page when viewing a job but does not completely sanitize input, making it possible to add notes with HTML tags and JavaScr... Read more
Affected Products :- Published: Aug. 02, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-1565
A vulnerability was found in FeiFeiCMS 2.7.130201. It has been classified as problematic. This affects an unknown part of the file \Public\system\slide_add.html of the component Extension Tool. The manipulation leads to cross site scripting. It is possibl... Read more
Affected Products : feifeicms- Published: Mar. 22, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-45843
Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Nextend Smart Slider 3 plugin <= 3.5.1.9 versions.... Read more
Affected Products : smart_slider_3- Published: Mar. 23, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-48429
In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible ... Read more
Affected Products : hub- Published: Mar. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0589
The WP Image Carousel WordPress plugin through 1.0.2 does not sanitise and escape some parameters, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.... Read more
Affected Products : wp_image_carousel- Published: Mar. 27, 2023
- Modified: May. 05, 2025
-
5.4
MEDIUMCVE-2023-1703
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.... Read more
Affected Products : pimcore- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-19277
Cross Site Scripting vulnerability found in Phachon mm-wiki v.0.1.2 allows a remote attacker to execute arbitrary code via javascript code in the markdown editor.... Read more
Affected Products : mm-wiki- Published: Apr. 04, 2023
- Modified: Feb. 13, 2025
-
5.4
MEDIUMCVE-2023-1871
The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the deleteLang function. This makes it possible for unauthenticated attackers... Read more
Affected Products : yourchannel- Published: Apr. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1879
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.... Read more
Affected Products : phpmyfaq- Published: Apr. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1883
Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.12.... Read more
Affected Products : phpmyfaq- Published: Apr. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-24747
Jfinal CMS v5.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list.... Read more
Affected Products : jfinal_cms- Published: Apr. 05, 2023
- Modified: Feb. 13, 2025
-
5.4
MEDIUMCVE-2022-4827
The WP Tiles WordPress plugin through 1.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Store... Read more
Affected Products : wp_tiles- Published: Apr. 10, 2023
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2023-24721
A cross-site scripting (XSS) vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary web scripts or HTML.... Read more
Affected Products : livesp- Published: Apr. 10, 2023
- Modified: Feb. 11, 2025
-
5.4
MEDIUMCVE-2025-22543
Missing Authorization vulnerability in Beautiful Templates ST Gallery WP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ST Gallery WP: from n/a through 1.0.8.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2022-45849
Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4 versions.... Read more
Affected Products : activello_theme- Published: Apr. 16, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-27777
Cross-site scripting (XSS) vulnerability was discovered in Online Jewelry Shop v1.0 that allows attackers to execute arbitrary script via a crafted URL.... Read more
Affected Products : online_jewelry_shop- Published: Apr. 19, 2023
- Modified: Feb. 05, 2025
-
5.4
MEDIUMCVE-2024-56377
A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a user receives a survey and clicks anywhere on the survey ... Read more
Affected Products : redcap- Published: Jan. 09, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-0424
The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authenticated users, such as Subscribers to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : ms-reviews- Published: Apr. 24, 2023
- Modified: Feb. 04, 2025