Latest CVE Feed
-
5.4
MEDIUMCVE-2024-53457
A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.... Read more
Affected Products : librenms- Published: Dec. 05, 2024
- Modified: Apr. 07, 2025
-
5.4
MEDIUMCVE-2024-11321
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hi e-learning Learning Management System (LMS) allows Reflected XSS.This issue affects Learning Management System (LMS): before 06.12.2024.... Read more
Affected Products :- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
5.4
MEDIUMCVE-2017-20059
A vulnerability, which was classified as problematic, has been found in Elefant CMS 1.3.12-RC. Affected by this issue is some unknown functionality of the component Title Handler. The manipulation with the input </title><img src=no onerror=alert(1)> leads... Read more
Affected Products : elefant_cms- Published: Jun. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-12253
The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'save_settings', 'export_csv', and 'simpleecommcart-action' actions in all versions ... Read more
Affected Products : simple-e-commerce-shopping-cart- Published: Dec. 07, 2024
- Modified: Dec. 07, 2024
-
5.4
MEDIUMCVE-2023-23868
Missing Authorization vulnerability in WPFactory Cost of Goods for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cost of Goods for WooCommerce: from n/a through 2.8.6.... Read more
Affected Products : cost_of_goods_for_woocommerce- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
5.4
MEDIUMCVE-2021-41432
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.... Read more
Affected Products : flatpress- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-25469
Missing Authorization vulnerability in Magazine3 Easy Table of Contents allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Table of Contents: from n/a through 2.0.45.2.... Read more
Affected Products : easy_table_of_contents- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
5.4
MEDIUMCVE-2022-33113
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.... Read more
Affected Products : jfinal_cms- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-25959
Missing Authorization vulnerability in Apollo13Themes Apollo13 Framework Extensions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apollo13 Framework Extensions: from n/a through 1.8.10.... Read more
Affected Products : apollo13_framework_extensions- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
5.4
MEDIUMCVE-2023-29433
Missing Authorization vulnerability in 腾讯云 tencentcloud-cos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects tencentcloud-cos: from n/a through 1.0.7.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
5.4
MEDIUMCVE-2017-20094
A vulnerability, which was classified as problematic, has been found in NewStatPress Plugin 1.2.4. This issue affects some unknown processing. The manipulation leads to basic cross site scripting (Persistent). The attack may be initiated remotely. Upgradi... Read more
Affected Products : newstatpress- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-49757
Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.1.10.... Read more
Affected Products : awesome_support- Published: Dec. 09, 2024
- Modified: May. 29, 2025
-
5.4
MEDIUMCVE-2022-27238
BigBlueButton version 2.4.7 (or earlier) is vulnerable to stored Cross-Site Scripting (XSS) in the private chat functionality. A threat actor could inject JavaScript payload in his/her username. The payload gets executed in the browser of the victim each ... Read more
Affected Products : bigbluebutton- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20544
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitat... Read more
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38871
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials ... Read more
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-54217
Missing Authorization vulnerability in Repute info systems ARForms.This issue affects ARForms: from n/a through 6.4.1.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
5.4
MEDIUMCVE-2022-23896
Admidio 4.1.2 version is affected by stored cross-site scripting (XSS).... Read more
Affected Products : admidio- Published: Jun. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-20113
A vulnerability, which was classified as problematic, was found in TrueConf Server 4.3.7. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been dis... Read more
Affected Products : server- Published: Jun. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-20122
A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Affected by this vulnerability is an unknown functionality of the component Contact Form. The manipulation of the argument text with the input <img src="http://1"; on o... Read more
Affected Products : bitrix_site_manager- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-20036
A vulnerability, which was classified as problematic, was found in PHPList 3.2.6. Affected is an unknown function of the file /lists/admin/ of the component Bounce Rule. The manipulation leads to cross site scripting (Persistent). It is possible to launch... Read more
Affected Products : phplist- Published: Jun. 10, 2022
- Modified: Nov. 21, 2024