Latest CVE Feed
-
5.4
MEDIUMCVE-2022-30456
Badminton Center Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /bcms/classes/Master.php?f=save_court_rental.... Read more
Affected Products : badminton_center_management_system- Published: May. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-30464
ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to Cross Site Scripting (XSS) via /simple_chat_bot/classes/Master.php?f=save_response.... Read more
Affected Products : chatbot_app_with_suggestion- Published: May. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-50965
Cross Site Scripting vulnerability in Public Knowledge Project PKP Platform OJS/OMP/OPS- before v.3.3.0.16 allows an attacker to execute arbitrary code and escalate privileges via a crafted script... Read more
Affected Products :- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
5.4
MEDIUMCVE-2024-37783
A reflected cross-site scripting (XSS) vulnerability in Gladinet CentreStack v13.12.9934.54690 allows attackers to inject malicious JavaScript into the web browser of a victim via the sessionId parameter at /portal/ForgotPassword.aspx.... Read more
Affected Products :- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
5.4
MEDIUMCVE-2024-11660
A vulnerability was found in code-projects Farmacia 1.0. It has been classified as problematic. This affects an unknown part of the file usuario.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attac... Read more
- Published: Nov. 25, 2024
- Modified: Dec. 04, 2024
-
5.4
MEDIUMCVE-2022-30429
Multiple cross-site scripting (XSS) vulnerabilities in Neos CMS allow attackers with the editor role or higher to inject arbitrary script or HTML code using the editor function, the deletion of assets, or a workspace title. The vulnerabilities were found ... Read more
Affected Products : neos_cms- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29770
XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.... Read more
Affected Products : xxl-job- Published: Jun. 03, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-36524
A vulnerability was found in Refined Toolkit. It has been rated as problematic. Affected by this issue is some unknown functionality of the component UI-Image/UI-Button. The manipulation leads to cross site scripting. The attack may be launched remotely. ... Read more
Affected Products : refined_toolkit- Published: Jun. 07, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-36544
A vulnerability has been found in SialWeb CMS and classified as problematic. This vulnerability affects unknown code of the component Search Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has bee... Read more
Affected Products : sialweb_cms- Published: Jun. 08, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-25037
A vulnerability was found in Thomson TCW710 ST5D.10.05 and classified as problematic. Affected by this issue is some unknown functionality of the file /goform/RgDdns. The manipulation of the argument DdnsHostName with the input ><script>alert(1)</script> ... Read more
- Published: Jun. 12, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-36624
Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.... Read more
Affected Products :- Published: Nov. 29, 2024
- Modified: Nov. 29, 2024
-
5.4
MEDIUMCVE-2024-11996
A vulnerability was found in code-projects Farmacia 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /editar-fornecedor.php. The manipulation of the argument cidade leads to cross site scripting. The atta... Read more
- Published: Nov. 30, 2024
- Modified: Dec. 04, 2024
-
5.4
MEDIUMCVE-2022-1549
The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor does it escape the values when outputting them back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability.... Read more
Affected Products : wp_athletics- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-53761
Cross-Site Request Forgery (CSRF) vulnerability in P. Roy WP Revisions Manager allows Cross Site Request Forgery.This issue affects WP Revisions Manager: from n/a through 1.0.2.... Read more
Affected Products :- Published: Dec. 02, 2024
- Modified: Dec. 02, 2024
-
5.4
MEDIUMCVE-2022-29406
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in DynamicWebLab's WordPress Team Manager plugin <= 1.6.9 at WordPress.... Read more
Affected Products : wp-team-manager- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-40745
Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8.... Read more
Affected Products : convert_forms- Published: Dec. 04, 2024
- Modified: Jun. 04, 2025
-
5.4
MEDIUMCVE-2022-31914
Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via zms/admin/public_html/save_animal?an_id=24.... Read more
- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-31301
Haraj v3.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Post Ads component.... Read more
Affected Products : haraj- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36608
Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /projects/editproject.php.... Read more
Affected Products : webtareas- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-53457
A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.... Read more
Affected Products : librenms- Published: Dec. 05, 2024
- Modified: Apr. 07, 2025