Latest CVE Feed
-
5.4
MEDIUMCVE-2025-51655
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php.... Read more
Affected Products : semcms- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2022-47413
Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II") XSS condition. ... Read more
Affected Products : openkm- Published: Feb. 07, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2022-47415
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the in-app messaging system (both subject and message bodies).... Read more
Affected Products : logicaldoc- Published: Feb. 07, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2023-0712
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_move_object function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber... Read more
Affected Products : wicked_folders- Published: Feb. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0736
Cross-site Scripting (XSS) - Stored in GitHub repository wallabag/wallabag prior to 2.5.4.... Read more
Affected Products : wallabag- Published: Feb. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0720
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subs... Read more
Affected Products : wicked_folders- Published: Feb. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0379
The Spotlight Social Feeds WordPress plugin before 1.4.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Sto... Read more
Affected Products : spotlight_social_feeds- Published: Feb. 13, 2023
- Modified: Mar. 21, 2025
-
5.4
MEDIUMCVE-2025-46732
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.6.6, an IDOR vulnerability in the GrapQL `NotificationLineNotificationMarkReadMutation` and `NotificationLineNotificationDeleteMutation... Read more
Affected Products : opencti- Published: Jul. 18, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2021-40555
Cross site scripting (XSS) vulnerability in flatCore-CMS 2.2.15 allows attackers to execute arbitrary code via description field on the new page creation form.... Read more
- Published: Feb. 16, 2023
- Modified: Mar. 19, 2025
-
5.4
MEDIUMCVE-2025-51397
A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists.... Read more
Affected Products : live_helper_chat- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2022-4622
The Login Logout Menu WordPress plugin through 1.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perf... Read more
Affected Products : login_logout_menu- Published: Feb. 21, 2023
- Modified: Mar. 12, 2025
-
5.4
MEDIUMCVE-2022-4784
The Hueman Addons WordPress plugin through 2.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform ... Read more
Affected Products : hueman_addons- Published: Feb. 21, 2023
- Modified: Mar. 14, 2025
-
5.4
MEDIUMCVE-2023-0380
The Easy Digital Downloads WordPress plugin before 3.1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform S... Read more
Affected Products : easy_digital_downloads- Published: Feb. 21, 2023
- Modified: Mar. 14, 2025
-
5.4
MEDIUMCVE-2022-46786
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 2 of 2).... Read more
Affected Products : dashboard_server- Published: Feb. 23, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1146
Cross-site Scripting (XSS) - Generic in GitHub repository flatpressblog/flatpress prior to 1.3.... Read more
Affected Products : flatpress- Published: Mar. 02, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-22438
Cross-site scripting vulnerability in Contents Management of EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 to 4.1.2-p1, and EC-CUBE 4.2.0), EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p5), and EC-CUBE 2 series (EC-CUBE 2.11.0 to 2.11.5, EC-CUBE... Read more
Affected Products : ec-cube- Published: Mar. 06, 2023
- Modified: Mar. 07, 2025
-
5.4
MEDIUMCVE-2015-10093
A vulnerability was found in Mark User as Spammer Plugin 1.0.0/1.0.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function user_row_actions of the file plugin/plugin.php. The manipulation of the argument url lea... Read more
Affected Products : mark_user_as_spammer- Published: Mar. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0069
The WPaudio MP3 Player WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to per... Read more
Affected Products : wpaudio_mp3_player- Published: Mar. 06, 2023
- Modified: Mar. 05, 2025
-
5.4
MEDIUMCVE-2022-4930
A vulnerability classified as problematic was found in nuxsmin sysPass up to 3.2.4. Affected by this vulnerability is an unknown functionality of the component URL Handler. The manipulation leads to cross site scripting. The attack can be launched remotel... Read more
Affected Products : syspass- Published: Mar. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1270
Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.... Read more
Affected Products : btcpayserver- Published: Mar. 08, 2023
- Modified: Nov. 21, 2024