Latest CVE Feed
-
5.4
MEDIUMCVE-2023-1871
The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the deleteLang function. This makes it possible for unauthenticated attackers... Read more
Affected Products : yourchannel- Published: Apr. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1879
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.... Read more
Affected Products : phpmyfaq- Published: Apr. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1883
Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.12.... Read more
Affected Products : phpmyfaq- Published: Apr. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-24747
Jfinal CMS v5.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list.... Read more
Affected Products : jfinal_cms- Published: Apr. 05, 2023
- Modified: Feb. 13, 2025
-
5.4
MEDIUMCVE-2022-4827
The WP Tiles WordPress plugin through 1.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Store... Read more
Affected Products : wp_tiles- Published: Apr. 10, 2023
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2023-24721
A cross-site scripting (XSS) vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary web scripts or HTML.... Read more
Affected Products : livesp- Published: Apr. 10, 2023
- Modified: Feb. 11, 2025
-
5.4
MEDIUMCVE-2025-22543
Missing Authorization vulnerability in Beautiful Templates ST Gallery WP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ST Gallery WP: from n/a through 1.0.8.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2022-45849
Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4 versions.... Read more
Affected Products : activello_theme- Published: Apr. 16, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-27777
Cross-site scripting (XSS) vulnerability was discovered in Online Jewelry Shop v1.0 that allows attackers to execute arbitrary script via a crafted URL.... Read more
Affected Products : online_jewelry_shop- Published: Apr. 19, 2023
- Modified: Feb. 05, 2025
-
5.4
MEDIUMCVE-2024-56377
A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a user receives a survey and clicks anywhere on the survey ... Read more
Affected Products : redcap- Published: Jan. 09, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-0424
The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authenticated users, such as Subscribers to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : ms-reviews- Published: Apr. 24, 2023
- Modified: Feb. 04, 2025
-
5.4
MEDIUMCVE-2022-27979
A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment Body component.... Read more
Affected Products : tooljet- Published: Apr. 26, 2023
- Modified: Feb. 03, 2025
-
5.4
MEDIUMCVE-2023-2350
A vulnerability classified as problematic was found in SourceCodester Service Provider Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Users.php. The manipulation of the argument id leads to cross sit... Read more
Affected Products : service_provider_management_system- Published: Apr. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-43871
IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials ... Read more
- Published: Apr. 29, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-45801
Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web based applications that construct LDAP statements based on user input. When an application fails to properly sanitize user input, it's po... Read more
Affected Products : streampark- Published: May. 01, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1861
The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : limit_login_attempts- Published: May. 02, 2023
- Modified: Jan. 30, 2025
-
5.4
MEDIUMCVE-2023-30184
A stored cross-site scripting (XSS) vulnerability in Typecho v1.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter at /index.php/archives/1/comment.... Read more
Affected Products : typecho- Published: May. 04, 2023
- Modified: Jan. 29, 2025
-
5.4
MEDIUMCVE-2023-30095
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the channel description field.... Read more
Affected Products : messenger- Published: May. 04, 2023
- Modified: Jan. 29, 2025
-
5.4
MEDIUMCVE-2023-0268
The Mega Addons For WPBakery Page Builder WordPress plugin before 4.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor rol... Read more
Affected Products : mega_addons_for_wpbakery_page_builder- Published: May. 08, 2023
- Modified: Jan. 28, 2025
-
5.4
MEDIUMCVE-2022-27856
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Atlas Gondal Export All URLs plugin <= 4.1 versions.... Read more
Affected Products : export_all_urls- Published: May. 10, 2023
- Modified: Nov. 21, 2024