Latest CVE Feed
-
5.4
MEDIUMCVE-2022-39338
user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery urls which may lead to a stored cross site scripting attack vector. The impact is limited due to the restrictive CSP that is applied on ... Read more
- Published: Nov. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-6345
A vulnerability was found in SourceCodester My Food Recipe 1.0 and classified as problematic. Affected by this issue is the function addRecipeModal of the file /endpoint/add-recipe.php of the component Add Recipe Page. The manipulation of the argument Nam... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2022-4253
A vulnerability was found in SourceCodester Canteen Management System. It has been declared as problematic. This vulnerability affects the function builtin_echo of the file customer.php. The manipulation leads to cross site scripting. The attack can be in... Read more
Affected Products : canteen_management_system- Published: Dec. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-44948
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=entities/entities_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a c... Read more
Affected Products : rukovoditel- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2022-4218
The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the list_quizzes() function. This makes it possible for unauthenticated attackers to de... Read more
Affected Products : chained_quiz- Published: Dec. 02, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2022-44731
A vulnerability has been identified in SIMATIC WinCC OA V3.15 (All versions < V3.15 P038), SIMATIC WinCC OA V3.16 (All versions < V3.16 P035), SIMATIC WinCC OA V3.17 (All versions < V3.17 P024), SIMATIC WinCC OA V3.18 (All versions < V3.18 P014). The affe... Read more
- Published: Dec. 13, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-43996
The csaf_provider package before 0.8.2 allows XSS via a crafted CSAF document uploaded as text/html. The endpoint upload allows valid CSAF advisories (JSON format) to be uploaded with Content-Type text/html and filenames ending in .html. When subsequently... Read more
Affected Products : csaf_provider- Published: Dec. 13, 2022
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2022-40373
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.... Read more
Affected Products : feehicms- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.4
MEDIUMCVE-2022-4587
A vulnerability, which was classified as problematic, has been found in Opencaching Deutschland oc-server3. This issue affects some unknown processing of the file htdocs/templates2/ocstyle/login.tpl of the component Login Page. The manipulation of the arg... Read more
Affected Products : oc-server3- Published: Dec. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4596
A vulnerability, which was classified as problematic, has been found in Shoplazza 1.1. This issue affects some unknown processing of the file /admin/api/admin/articles/ of the component Add Blog Post Handler. The manipulation of the argument Title leads t... Read more
Affected Products : lifestyle- Published: Dec. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4597
A vulnerability, which was classified as problematic, was found in Shoplazza LifeStyle 1.1. Affected is an unknown function of the file /admin/api/admin/v2_products of the component Create Product Handler. The manipulation leads to cross site scripting. I... Read more
Affected Products : lifestyle- Published: Dec. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4599
A vulnerability was found in Shoplazza LifeStyle 1.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/api/theme-edit/ of the component Product Handler. The manipulation of the argument Subheading/Headi... Read more
Affected Products : lifestyle- Published: Dec. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4614
Cross-site Scripting (XSS) - Stored in GitHub repository alagrede/znote-app prior to 1.7.11.... Read more
Affected Products : znote- Published: Dec. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-44380
Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.... Read more
Affected Products : snipe-it- Published: Dec. 25, 2022
- Modified: Apr. 15, 2025
-
5.4
MEDIUMCVE-2022-29853
OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.... Read more
Affected Products : open-xchange_appsuite- Published: Dec. 26, 2022
- Modified: Apr. 14, 2025
-
5.4
MEDIUMCVE-2019-25086
A vulnerability was found in IET-OU Open Media Player up to 1.5.0. It has been declared as problematic. This vulnerability affects the function webvtt of the file application/controllers/timedtext.php. The manipulation of the argument ttml_url leads to cr... Read more
Affected Products : open_media_player- Published: Dec. 27, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4362
The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : popup_maker- Published: Jan. 02, 2023
- Modified: Apr. 10, 2025
-
5.4
MEDIUMCVE-2022-4881
A vulnerability was found in CapsAdmin PAC3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file lua/pac3/core/shared/http.lua. The manipulation of the argument url leads to cross site scripting. The attack m... Read more
Affected Products : pac3- Published: Jan. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-46769
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.2 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in ... Read more
Affected Products : sling_cms- Published: Jan. 09, 2023
- Modified: Apr. 09, 2025