Latest CVE Feed
-
5.4
MEDIUMCVE-2023-43873
A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Name filed in the Manage Menu.... Read more
Affected Products : e107_cms- Published: Sep. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-26148
All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers. An attacker can add the \r\n (carriage return line feeds) characters and inject additional headers in the request sent.... Read more
Affected Products : libhv- Published: Sep. 29, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43878
Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload into the Main Menu Items in the Administration Menu.... Read more
Affected Products : ritecms- Published: Sep. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43706
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "email_templates_key" parameter, potentially leading to unauthorized execution of scripts within a user's web ... Read more
Affected Products : oscommerce- Published: Sep. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43708
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "configuration_title[1](MODULE_PAYMENT_SAGE_PAY_SERVER_TEXT_TITLE)" parameter, potentially leading to unauthor... Read more
Affected Products : oscommerce- Published: Sep. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43709
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "configuration_title[1](MODULE)" parameter, potentially leading to unauthorized execution of scripts within a ... Read more
Affected Products : oscommerce- Published: Sep. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43717
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MSEARCH_HIGHLIGHT_ENABLE_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within... Read more
Affected Products : oscommerce- Published: Sep. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43726
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_products_status_manual_name_long[1]" parameter, potentially leading to unauthorized execution of scrip... Read more
Affected Products : oscommerce- Published: Sep. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43734
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.... Read more
Affected Products : oscommerce- Published: Sep. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-39429
Cross-site scripting vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to inject an arbitrary script via a crafted configuration. Affected products and versions are as follows: ACERA 1210 firmware ver.02.36 and... Read more
- Published: Oct. 03, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43951
SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Column Management component.... Read more
- Published: Oct. 03, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-44758
GDidees CMS 3.0 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to the Page Title.... Read more
Affected Products : gdidees_cms- Published: Oct. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-44770
A Cross-Site Scripting (XSS) vulnerability in Zenario CMS v.9.4.59197 allows an attacker to execute arbitrary code via a crafted script to the Organizer - Spare alias.... Read more
Affected Products : zenario- Published: Oct. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1655
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially ... Read more
- Published: Mar. 23, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-34354
A stored cross-site scripting (XSS) vulnerability exists in the upload_brand.cgi functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to execution of arbitrary javascript in another user's browser. An attacker... Read more
- Published: Oct. 11, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-9015
dsmall v20180320 allows XSS via the public/index.php/home/predeposit/index.html pdr_sn parameter (aka the CMS search box).... Read more
Affected Products : dsmall- Published: Mar. 25, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-27312
SnapCenter Plugin for VMware vSphere versions 4.6 prior to 4.9 are susceptible to a vulnerability which may allow authenticated unprivileged users to modify email and snapshot name settings within the VMware vSphere user interface. ... Read more
Affected Products : snapcenter_plug-in- Published: Oct. 12, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-3746
The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : activitypub- Published: Oct. 16, 2023
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2023-4646
The Simple Posts Ticker WordPress plugin before 1.1.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to per... Read more
Affected Products : simple_posts_ticker- Published: Oct. 16, 2023
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2023-4798
The User Avatar WordPress plugin before 1.2.2 does not properly sanitize and escape certain of its shortcodes attributes, which could allow relatively low-privileged users like contributors to conduct Stored XSS attacks.... Read more
Affected Products : user_avatar-reloaded- Published: Oct. 16, 2023
- Modified: Nov. 21, 2024