Latest CVE Feed
-
5.4
MEDIUMCVE-2022-42119
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.... Read more
- Published: Nov. 15, 2022
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2022-41805
Cross-Site Request Forgery (CSRF) vulnerability in Booster for WooCommerce plugin <= 5.6.6 on WordPress.... Read more
Affected Products : booster_for_woocommerce- Published: Nov. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-35500
Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality.... Read more
Affected Products : blog_pro- Published: Nov. 23, 2022
- Modified: Apr. 28, 2025
-
5.4
MEDIUMCVE-2022-39338
user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery urls which may lead to a stored cross site scripting attack vector. The impact is limited due to the restrictive CSP that is applied on ... Read more
- Published: Nov. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-6345
A vulnerability was found in SourceCodester My Food Recipe 1.0 and classified as problematic. Affected by this issue is the function addRecipeModal of the file /endpoint/add-recipe.php of the component Add Recipe Page. The manipulation of the argument Nam... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2022-4253
A vulnerability was found in SourceCodester Canteen Management System. It has been declared as problematic. This vulnerability affects the function builtin_echo of the file customer.php. The manipulation leads to cross site scripting. The attack can be in... Read more
Affected Products : canteen_management_system- Published: Dec. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-44948
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=entities/entities_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a c... Read more
Affected Products : rukovoditel- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2022-4218
The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the list_quizzes() function. This makes it possible for unauthenticated attackers to de... Read more
Affected Products : chained_quiz- Published: Dec. 02, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2022-44731
A vulnerability has been identified in SIMATIC WinCC OA V3.15 (All versions < V3.15 P038), SIMATIC WinCC OA V3.16 (All versions < V3.16 P035), SIMATIC WinCC OA V3.17 (All versions < V3.17 P024), SIMATIC WinCC OA V3.18 (All versions < V3.18 P014). The affe... Read more
- Published: Dec. 13, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-43996
The csaf_provider package before 0.8.2 allows XSS via a crafted CSAF document uploaded as text/html. The endpoint upload allows valid CSAF advisories (JSON format) to be uploaded with Content-Type text/html and filenames ending in .html. When subsequently... Read more
Affected Products : csaf_provider- Published: Dec. 13, 2022
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2022-40373
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.... Read more
Affected Products : feehicms- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.4
MEDIUMCVE-2022-4587
A vulnerability, which was classified as problematic, has been found in Opencaching Deutschland oc-server3. This issue affects some unknown processing of the file htdocs/templates2/ocstyle/login.tpl of the component Login Page. The manipulation of the arg... Read more
Affected Products : oc-server3- Published: Dec. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4596
A vulnerability, which was classified as problematic, has been found in Shoplazza 1.1. This issue affects some unknown processing of the file /admin/api/admin/articles/ of the component Add Blog Post Handler. The manipulation of the argument Title leads t... Read more
Affected Products : lifestyle- Published: Dec. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4597
A vulnerability, which was classified as problematic, was found in Shoplazza LifeStyle 1.1. Affected is an unknown function of the file /admin/api/admin/v2_products of the component Create Product Handler. The manipulation leads to cross site scripting. I... Read more
Affected Products : lifestyle- Published: Dec. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4599
A vulnerability was found in Shoplazza LifeStyle 1.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/api/theme-edit/ of the component Product Handler. The manipulation of the argument Subheading/Headi... Read more
Affected Products : lifestyle- Published: Dec. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4614
Cross-site Scripting (XSS) - Stored in GitHub repository alagrede/znote-app prior to 1.7.11.... Read more
Affected Products : znote- Published: Dec. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-44380
Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.... Read more
Affected Products : snipe-it- Published: Dec. 25, 2022
- Modified: Apr. 15, 2025
-
5.4
MEDIUMCVE-2022-29853
OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.... Read more
Affected Products : open-xchange_appsuite- Published: Dec. 26, 2022
- Modified: Apr. 14, 2025
-
5.4
MEDIUMCVE-2019-25086
A vulnerability was found in IET-OU Open Media Player up to 1.5.0. It has been declared as problematic. This vulnerability affects the function webvtt of the file application/controllers/timedtext.php. The manipulation of the argument ttml_url leads to cr... Read more
Affected Products : open_media_player- Published: Dec. 27, 2022
- Modified: Nov. 21, 2024