Latest CVE Feed
-
5.4
MEDIUMCVE-2025-32068
Incorrect Authorization vulnerability in The Wikimedia Foundation Mediawiki - OAuth Extension allows Authentication Bypass.This issue affects Mediawiki - OAuth Extension: from 1.39 through 1.43.... Read more
Affected Products :- Published: Apr. 11, 2025
- Modified: Jul. 07, 2025
-
5.4
MEDIUMCVE-2019-18571
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a reflected cross-site scripting vulnerability in the My Access Live module [MAL]. An authenticated malicious local user could potentially e... Read more
Affected Products : rsa_identity_governance_and_lifecycle- EPSS Score: %0.38
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-7552
An issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Section. This is due to lack of sanitization in the Edit Name section.... Read more
Affected Products : investment_mlm_software- EPSS Score: %0.21
- Published: Jun. 06, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-8157
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate downloadable link and cause an invocation of error handling that acceses user input witho... Read more
Affected Products : magento- EPSS Score: %0.18
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-8288
Vulnerability in Online Store v1.0, Stored XSS in user_view.php where adidas_member_user variable is not sanitized.... Read more
Affected Products : online_store_system- EPSS Score: %0.26
- Published: Oct. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-8289
Vulnerability in Online Store v1.0, stored XSS in admin/user_view.php adidas_member_email variable... Read more
Affected Products : online_store_system- EPSS Score: %0.26
- Published: Oct. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-7934
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify these fields with a particular XSS payload, and it will... Read more
Affected Products : liferay_portal- EPSS Score: %3.29
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-3451
Vulnerability in the Oracle Retail Open Commerce Platform component of Oracle Retail Applications (subcomponent: Web). Supported versions that are affected are 4.0, 5.0, 5.1, 5.3, 6.0,6.1, 15.0 and 16.0. Easily "exploitable" vulnerability allows low privi... Read more
Affected Products : retail_open_commerce_platform_cloud_service- EPSS Score: %0.20
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2018-14541
PHP Scripts Mall Basic B2B Script 2.0.0 has Reflected and Stored XSS via the First name, Last name, Address 1, City, State, and Company name fields.... Read more
- EPSS Score: %0.21
- Published: Aug. 04, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9016
Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.17
- Published: Feb. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-5932
IBM Connections 4.0, 4.5, 5.0, and 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a ... Read more
Affected Products : connections- EPSS Score: %0.26
- Published: Mar. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-0683
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to Search Framework.... Read more
Affected Products : peoplesoft_enterprise_peopletools- EPSS Score: %0.14
- Published: Apr. 21, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2017-3847
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. More Information: CSCvc72741. Known Affected Releas... Read more
- EPSS Score: %0.19
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2020-0656
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'.... Read more
Affected Products : dynamics_365- EPSS Score: %0.72
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-14869
PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field in a profile.... Read more
Affected Products : php_template_store_script- EPSS Score: %0.11
- Published: Aug. 06, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24250
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from lack of sanitisation in the label of the Form Fields, leading to Authenticated Stored Cross-Site Scripting issues across various pages of t... Read more
- EPSS Score: %0.19
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24365
The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for tables. Each column had a type. The type "Custom Field" allowed to choose an arbitrary database column to display in the table. There was... Read more
Affected Products : admin_columns- EPSS Score: %0.30
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24464
The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site Scripti... Read more
Affected Products : youtube_embed\,_playlist_and_popup- EPSS Score: %0.21
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44299
A reflected cross-site scripting (XSS) vulnerability in \lib\packages\themes\themes.php of Navigate CMS v2.9.4 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : navigate_cms- EPSS Score: %0.22
- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-15190
PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field.... Read more
Affected Products : hotel_booking_script- EPSS Score: %0.21
- Published: Aug. 10, 2018
- Modified: Nov. 21, 2024