Latest CVE Feed
-
5.4
MEDIUMCVE-2021-20477
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sess... Read more
Affected Products : planning_analytics- Published: Jun. 29, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-35468
A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.... Read more
Affected Products : human_resource_management_system- Published: May. 30, 2024
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2020-4935
IBM Datacap Fastdoc Capture (IBM Datacap Navigator 9.1.7 ) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials ... Read more
- Published: Jul. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-2470
The Simple Ajax Chat WordPress plugin before 20240412 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disal... Read more
Affected Products : simple_ajax_chat- Published: Jun. 04, 2024
- Modified: May. 21, 2025
-
5.4
MEDIUMCVE-2020-23208
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Send test" field under the "Start or continue campaign" module.... Read more
Affected Products : phplist- Published: Jul. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-47513
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in ARI Soft ARI Stream Quiz allows Code Injection.This issue affects ARI Stream Quiz: from n/a through 1.3.2.... Read more
Affected Products : ari_stream_quiz- Published: Jun. 04, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-36397
A stored cross site scripting (XSS) vulnerability in the /admin/contact/contact component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "New" parameter.... Read more
Affected Products : lavalite- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-36399
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "rule1" parameter under the "Bounce Rules" module.... Read more
Affected Products : phplist- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-36412
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Search Text" field under the "Admin Search" module.... Read more
Affected Products : cms_made_simple- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-36413
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Exclude these IP addresses from the "Site Down" status" parameter under ... Read more
Affected Products : cms_made_simple- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-36414
A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "URL (slug)" or "Extra" fields under the "Add Article" feature.... Read more
Affected Products : cms_made_simple- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-0756
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.... Read more
Affected Products : insert_or_embed_articulate_content- Published: Jun. 04, 2024
- Modified: Mar. 13, 2025
-
5.4
MEDIUMCVE-2020-23697
Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.... Read more
Affected Products : monstra_cms- Published: Jul. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-30889
Cross Site Scripting vulnerability in audimex audimexEE v.15.1.2 and fixed in 15.1.3.9 allows a remote attacker to execute arbitrary code via the service, method, widget_type, request_id, payload parameters.... Read more
Affected Products : audimexee- Published: Jun. 04, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-5127
In lunary-ai/lunary versions 1.2.2 through 1.2.25, an improper access control vulnerability allows users on the Free plan to invite other members and assign them any role, including those intended for Paid and Enterprise plans only. This issue arises due ... Read more
Affected Products : lunary- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-4468
The Salon booking system plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions hooked into admin_init in all versions up to, and including, 9.9. This makes it possible for... Read more
Affected Products : salon_booking_system- Published: Jun. 08, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25875
A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload entered into the 'Smiley Code' parameter.... Read more
Affected Products : codoforum- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-35984
A stored cross site scripting (XSS) vulnerability in the 'Users Alerts' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' parameter.... Read more
Affected Products : rukovoditel- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-32797
Missing Authorization vulnerability in Martin Gibson WP LinkedIn Auto Publish.This issue affects WP LinkedIn Auto Publish: from n/a through 8.11.... Read more
Affected Products :- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29105
A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below may allow a remote authenticated attacker to pass and store malicious strings in the ArcGIS Services Directory.... Read more
Affected Products : arcgis_server- Published: Jul. 11, 2021
- Modified: Nov. 21, 2024