Latest CVE Feed
-
5.4
MEDIUMCVE-2024-9299
A vulnerability classified as problematic has been found in SourceCodester Online Railway Reservation System 1.0. This affects an unknown part of the file /?page=reserve. The manipulation of the argument First Name/Middle Name/Last Name leads to cross sit... Read more
Affected Products : railway_reservation_system- Published: Sep. 28, 2024
- Modified: Oct. 01, 2024
-
5.4
MEDIUMCVE-2024-46082
Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.... Read more
Affected Products : scriptcase- Published: Oct. 01, 2024
- Modified: Apr. 28, 2025
-
5.4
MEDIUMCVE-2024-33209
FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser.... Read more
Affected Products : flatpress- Published: Oct. 02, 2024
- Modified: Mar. 14, 2025
-
5.4
MEDIUMCVE-2024-20442
A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote attacker to perform limited Administrator actions on an affected device. This vulnerability is due to insufficient authorization con... Read more
- Published: Oct. 02, 2024
- Modified: Oct. 07, 2024
-
5.4
MEDIUMCVE-2021-43841
XWiki is a generic wiki platform offering runtime services for applications built on top of it. When using default XWiki configuration, it's possible for an attacker to upload an SVG containing a script executed when executing the download action on the f... Read more
Affected Products : xwiki- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-41514
A reflected cross-site scripting (XSS) vulnerability in "PrevPgGroup.aspx" in CADClick v1.11.0 and before allows remote attackers to inject arbitrary web script or HTML via the "wer" parameter.... Read more
Affected Products : cadclick- Published: Oct. 04, 2024
- Modified: Jun. 02, 2025
-
5.4
MEDIUMCVE-2022-0510
Cross-site Scripting (XSS) - Reflected in Packagist pimcore/pimcore prior to 10.3.1.... Read more
Affected Products : pimcore- Published: Feb. 08, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-47635
Cross-Site Request Forgery (CSRF) vulnerability in TinyPNG.This issue affects TinyPNG: from n/a through 3.4.3.... Read more
Affected Products :- Published: Oct. 05, 2024
- Modified: Oct. 07, 2024
-
5.4
MEDIUMCVE-2022-24590
A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to execute arbitrary web scripts or HTML.... Read more
- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44565
A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 7.6.1 via the xss_clean function in classes/Security.php, which allows remote malicious users to inject arbitrary JavaScript or HTML. An example of affected components are all Markdown... Read more
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-21286
Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Management product of Oracle PeopleSoft (component: Enterprise Learning Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024
-
5.4
MEDIUMCVE-2024-9873
The Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URLs in posts, comments, and profiles when Markdown support is enabled in all ver... Read more
Affected Products : peepso- Published: Oct. 16, 2024
- Modified: Oct. 16, 2024
-
5.4
MEDIUMCVE-2022-24612
An authenticated user can upload an XML file containing an XSS via the ITSM module of EyesOfNetwork 5.3.11, resulting in a stored XSS.... Read more
Affected Products : eyesofnetwork- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-7288
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_profile_preference function in versions up to, and including, 4.3.7. This makes it possible ... Read more
Affected Products : paytium- Published: Oct. 16, 2024
- Modified: Oct. 17, 2024
-
5.4
MEDIUMCVE-2023-7289
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the paytium_sw_save_api_keys function in versions up to, and including, 4.3.7. This makes it possible for ... Read more
Affected Products : paytium- Published: Oct. 16, 2024
- Modified: Oct. 17, 2024
-
5.4
MEDIUMCVE-2022-25409
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.... Read more
Affected Products : hospital_management_system- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-25413
Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3.... Read more
Affected Products : maxsite_cms- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-48037
Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget allows Cross Site Request Forgery.This issue affects Contact Form Widget: from n/a through 1.4.2.... Read more
Affected Products : contact_form_widget- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
5.4
MEDIUMCVE-2022-25022
A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.... Read more
Affected Products : htmly- Published: Mar. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-25138
Axelor Open Suite v5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Name parameter.... Read more
Affected Products : open_suite- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024