Latest CVE Feed
-
5.4
MEDIUMCVE-2021-31583
Sipwise C5 NGCP WWW Admin version 3.6.7 up to and including platform version NGCP CE 3.0 has multiple authenticated stored and reflected XSS vulnerabilities when input passed via several parameters to several scripts is not properly sanitized before being... Read more
Affected Products : next_generation_communication_platform- Published: Apr. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-24588
Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function.... Read more
Affected Products : flatpress- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-3224
A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter.... Read more
Affected Products : csz_cms- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-5280
SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.... Read more
- Published: Jan. 08, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38713
imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header.... Read more
Affected Products : imgurl- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38822
A Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that allows for arbitrary execution of JavaScript commands.... Read more
Affected Products : icehrm- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-33295
Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html.... Read more
Affected Products : joplin- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-39079
IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadi... Read more
Affected Products : cognos_analytics_mobile- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-39486
A Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, passwords or to run arbitrary code on a victim's browser.... Read more
Affected Products : gila_cms- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-26555
A stored cross-site scripting (XSS) vulnerability in the Add a Button function of Eova v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the button name text box.... Read more
Affected Products : eova- Published: Mar. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-2689
A vulnerability classified as problematic has been found in SourceCodester Wedding Hall Booking System. Affected is an unknown function of the file /whbs/?page=contact_us of the component Contact Page. The manipulation of the argument Message leads to cro... Read more
Affected Products : wedding_hall_booking_system- Published: Aug. 06, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-28448
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.... Read more
Affected Products : nopcommerce- Published: Apr. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-41948
A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List of subjects".... Read more
Affected Products : subrion- Published: Apr. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-18373
In the Schiocco "Support Board - Chat And Help Desk" plugin 1.2.3 for WordPress, a Stored XSS vulnerability has been discovered in file upload areas in the Chat and Help Desk sections via the msg parameter in a /wp-admin/admin-ajax.php sb_ajax_add_message... Read more
- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42220
A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box.... Read more
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37392
In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. When the API functions are enabled, the attacker can use API to update user nickname with XSS payload and achieve stored XSS. Users who view the art... Read more
Affected Products : rpcms- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29531
An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.... Read more
Affected Products : misp- Published: Apr. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37742
app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.... Read more
Affected Products : misp- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5701
The Skout: Chats. Friends. Fun. (aka com.skout.android) application 4.3.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate... Read more
Affected Products : skout\- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2021-38267
Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6, and Liferay DXP 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_blogs_web_... Read more
- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024