Latest CVE Feed
-
5.4
MEDIUMCVE-2021-38934
IBM Engineering Test Management 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-31923
Missing Authorization vulnerability in QuanticaLabs CSS3 Accordions for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CSS3 Accordions for WordPress: from n/a through 3.0.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-47556
Missing Authorization vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CSS3 Compare Pricing Tables for WordPress: from n/a through 11.5.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2022-25370
Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.05, and earlier versions, by leveraging a vulnerability in Birt (https://bugs.eclipse.org/bugs/show_bug.cg... Read more
Affected Products : ofbiz- Published: Sep. 02, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-1625
The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cro... Read more
Affected Products : qi_blocks- Published: May. 19, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-7657
A vulnerability classified as problematic was found in Gila CMS 1.10.9. This vulnerability affects unknown code of the file /cm/update_rows/page?id=2 of the component HTTP POST Request Handler. The manipulation of the argument content leads to cross site ... Read more
Affected Products : gila_cms- Published: Aug. 12, 2024
- Modified: Aug. 15, 2024
-
5.4
MEDIUMCVE-2025-32999
Cross-site scripting vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and prior to Ver. 3.0.47. This issue exists in a specific field in the entry editing screen, and exploitation requires contributor or higher level privileges. If this v... Read more
Affected Products : a-blog_cms- Published: May. 19, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2022-35194
TestLink v1.9.20 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /lib/inventory/inventoryView.php.... Read more
Affected Products : testlink- Published: Sep. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-37251
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.... Read more
Affected Products : craft_cms- Published: Sep. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-38550
A stored cross-site scripting (XSS) vulnerability in the /weibo/list component of Jeesns v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : jeesns- Published: Sep. 19, 2022
- Modified: May. 27, 2025
-
5.4
MEDIUMCVE-2022-3005
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.... Read more
- Published: Sep. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-37339
Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Meet My Team plugin <= 2.0.5 at WordPress.... Read more
Affected Products : meet_my_team- Published: Sep. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-37328
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in Themes Awesome History Timeline plugin <= 1.0.5 at WordPress.... Read more
Affected Products : timeline_awesome- Published: Sep. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-48488
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, deleting the file .htaccess allows an attacker to upload an HTML file containing malicious JavaScript code to the server, which can result in a Cross-Site Scripting (X... Read more
Affected Products : freescout- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-48875
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, the system's incorrect validation of last_name and first_name during profile data updates allows for the injection of arbitrary JavaScript code, which will be executed... Read more
Affected Products : freescout- Published: May. 30, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2021-41434
A stored Cross-Site Scripting (XSS) vulnerability exists in version 1.0 of the Expense Management System application that allows for arbitrary execution of JavaScript commands through index.php.... Read more
- Published: Sep. 28, 2022
- Modified: May. 20, 2025
-
5.4
MEDIUMCVE-2021-42047
An issue was discovered in the Growth extension in MediaWiki through 1.36.2. On any Wiki with the Mentor Dashboard feature enabled, users can login with a mentor account and trigger an XSS payload (such as alert) via Growthexperiments-mentor-dashboard-men... Read more
Affected Products : mediawiki- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3002
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.... Read more
- Published: Oct. 06, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-5507
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component MAC Filtering Page. The manipulation of the argument Comment leads to cros... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2022-40248
An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via form using the "Product Affected" field.... Read more
Affected Products : vince- Published: Oct. 10, 2022
- Modified: Nov. 21, 2024