Latest CVE Feed
-
5.4
MEDIUMCVE-2021-24712
The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new calendars.... Read more
Affected Products : appointment_hour_booking- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-39637
Server Side Request Forgery (SSRF) vulnerability in Pixelcurve Edubin edubin.This issue affects Edubin: from n/a through 9.2.0.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Nov. 04, 2024
-
5.4
MEDIUMCVE-2024-7368
A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /ajax.php?action=save_quiz. The manipulation of the argument title leads to cross site scri... Read more
Affected Products : simple_realtime_quiz_system- Published: Aug. 01, 2024
- Modified: Aug. 07, 2024
-
5.4
MEDIUMCVE-2020-19962
A stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.39, allows attackers to execute arbitrary web scripts.... Read more
Affected Products : chaoji_cms- Published: Oct. 14, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-3636
The Pinpoint Booking System WordPress plugin before 2.9.9.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability ... Read more
Affected Products : pinpoint_booking_system- Published: Aug. 05, 2024
- Modified: Jun. 06, 2025
-
5.4
MEDIUMCVE-2021-29878
IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials... Read more
Affected Products : business_automation_workflow- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-6766
The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to... Read more
Affected Products : shortcodes_ultimate- Published: Aug. 06, 2024
- Modified: Jun. 13, 2025
-
5.4
MEDIUMCVE-2024-7309
A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. This affects an unknown part of the file entry.php. The manipulation of the argument school leads to cross site scripting. It is possible to i... Read more
Affected Products : record_management_system- Published: Jul. 31, 2024
- Modified: Aug. 13, 2024
-
5.4
MEDIUMCVE-2024-7355
The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node_description' parameter in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This ma... Read more
Affected Products : organization_chart- Published: Aug. 07, 2024
- Modified: Mar. 01, 2025
-
5.4
MEDIUMCVE-2024-6884
The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.39 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and ab... Read more
Affected Products : gutenberg_blocks_with_ai- Published: Aug. 08, 2024
- Modified: May. 27, 2025
-
5.4
MEDIUMCVE-2024-40473
A Stored Cross Site Scripting (XSS) vulnerability was found in "manage_houses.php" in SourceCodester Best House Rental Management System v1.0. It allows remote attackers to execute arbitrary code via "House_no" and "Description" parameter fields.... Read more
Affected Products : best_house_rental_management_system- Published: Aug. 12, 2024
- Modified: Sep. 03, 2024
-
5.4
MEDIUMCVE-2020-23044
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.... Read more
Affected Products : dedecms- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-23049
Fork CMS Content Management System v5.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the `Displayname` field when using the `Add`, `Edit` or `Register' functions. This vulnerability allows attackers to execute arbitrary web sc... Read more
Affected Products : fork_cms- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-28955
SugarCRM v6.5.18 was discovered to contain a cross-site scripting (XSS) vulnerability in the Create Employee module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the First Name or Last Name input fi... Read more
Affected Products : sugarcrm- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-7685
A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this issue is some unknown functionality of the file adds.php. The manipulation of the argument name/dob/... Read more
Affected Products : advocate_office_management_system- Published: Aug. 12, 2024
- Modified: Aug. 20, 2024
-
5.4
MEDIUMCVE-2024-7686
A vulnerability, which was classified as problematic, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This affects an unknown part of the file register_case.php. The manipulation of the argument title/description/opposite_la... Read more
Affected Products : advocate_office_management_system- Published: Aug. 12, 2024
- Modified: Aug. 20, 2024
-
5.4
MEDIUMCVE-2024-33536
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability occurs due to inadequate input validation of the res parameter, allowing an authenticated attacker to inject and execute arbitrary JavaScript code within the context of ... Read more
Affected Products : collaboration- Published: Aug. 12, 2024
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2024-41735
SAP Commerce Backoffice does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability causing low impact on confidentiality and integrity of the application.... Read more
Affected Products : commerce_backoffice- Published: Aug. 13, 2024
- Modified: Sep. 12, 2024
-
5.4
MEDIUMCVE-2021-36698
Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.... Read more
Affected Products : pandora_fms- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42662
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the we... Read more
Affected Products : online_event_booking_and_reservation_system- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024