Latest CVE Feed
-
5.4
MEDIUMCVE-2022-28450
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser.... Read more
Affected Products : nopcommerce- Published: Apr. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1503
A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the file /admin/edit.php of the Content Module. The manipulation of the argument post-content with an input like <script>alert(1)</script> lea... Read more
Affected Products : getsimple_cms- Published: Apr. 27, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-50841
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/calendar_of_events.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the date_start, date_end, and t... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: May. 06, 2025
-
5.4
MEDIUMCVE-2024-52505
matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of the matrix-appservice-irc bridge up to version 3.0.2 contains a vulnerability which can lead to arbitrary IRC command execution as the bridge IRC bot.... Read more
Affected Products : matrix_irc_bridge- Published: Nov. 14, 2024
- Modified: Nov. 15, 2024
-
5.4
MEDIUMCVE-2021-3987
An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the `create_shelf` method in `shelf.py` not verifying if the ... Read more
Affected Products : calibre-web- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
5.4
MEDIUMCVE-2024-49759
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Manage User Access" page allows authenticated users to inject arbitrary JavaScript through the "bill_name" parameter when... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2024-49764
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Capture Debug Information" page allows authenticated users to inject arbitrary JavaScript through the "hostname" paramete... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2024-50350
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the "name" parameter when creating ... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2024-50352
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" section of the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "name... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
5.4
MEDIUMCVE-2024-51496
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "metric" parameter of the "/wireless" and "/health" endpoints allows attackers to inject arbitrary JavaScript. This vul... Read more
Affected Products : librenms- Published: Nov. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36912
Stored Cross-Site Scripting (XSS) vulnerability in Andrea Pernici News Sitemap for Google plugin <= 1.0.16 on WordPress, attackers must have contributor or higher user role.... Read more
Affected Products : google-news-sitemap- Published: May. 06, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-50803
The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileges... Read more
Affected Products : redaxo- Published: Nov. 19, 2024
- Modified: Jun. 13, 2025
-
5.4
MEDIUMCVE-2022-29976
An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 .... Read more
Affected Products : mdaemon- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-52585
Autolab is a course management service that enables auto-graded programming assignments. There is an HTML injection vulnerability in version 3.0.1 that can affect instructors and CAs on the grade submissions page. The issue is patched in version 3.0.2. On... Read more
Affected Products : autolab- Published: Nov. 18, 2024
- Modified: Jan. 21, 2025
-
5.4
MEDIUMCVE-2022-1557
The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating its settings, and is also lacking sanitisation as well as escaping in some of them, which could allow any authenticated users such as ... Read more
Affected Products : uleak-security-dashboard- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-51209
Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's Client Management System Version 1.2 allow local attackers to inject arbitrary web script or HTML via the search input field parameter to admin search invoice page and client search invoice page.... Read more
Affected Products : client_management_system- Published: Nov. 20, 2024
- Modified: Mar. 31, 2025
-
5.4
MEDIUMCVE-2024-48531
A reflected cross-site scripting (XSS) vulnerability on the Rental Availability module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.... Read more
Affected Products :- Published: Nov. 20, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-48535
A stored cross-site scripting (XSS) vulnerability in eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.... Read more
Affected Products :- Published: Nov. 20, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29449
Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Opal Hotel Room Booking plugin <= 1.2.7 at WordPress.... Read more
Affected Products : opal_hotel_room_booking- Published: May. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-45512
An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerability by creating a folder in the Briefcase module with a malicious payload and sharing it with a victim. When the victim interacts with th... Read more
Affected Products : zimbra_collaboration_suite- Published: Nov. 21, 2024
- Modified: Jun. 11, 2025