Latest CVE Feed
-
5.4
MEDIUMCVE-2022-34650
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.... Read more
Affected Products : team- EPSS Score: %0.18
- Published: Jul. 22, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3497
A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been classified as problematic. Affected is an unknown function of the component Master List. The manipulation of the argument city/state/country/position leads to cr... Read more
Affected Products : human_resource_management_system- EPSS Score: %0.08
- Published: Oct. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3503
A vulnerability was found in SourceCodester Purchase Order Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the component Supplier Handler. The manipulation of the argument Supplier Name/Address/Contac... Read more
Affected Products : purchase_order_management_system- EPSS Score: %0.08
- Published: Oct. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-19090
tianti 2.3 has stored XSS in the article management module via an article title.... Read more
Affected Products : tianti- EPSS Score: %0.21
- Published: Nov. 07, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20683
Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.... Read more
Affected Products : basercms- EPSS Score: %0.21
- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-36282
Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Roman Pronskiy's Search Exclude plugin <= 1.2.6 at WordPress.... Read more
Affected Products : search_exclude- EPSS Score: %0.27
- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-26847
A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the state parameter at opencats/index.php?m=candidates.... Read more
Affected Products : opencats- EPSS Score: %0.45
- Published: Apr. 11, 2023
- Modified: Feb. 11, 2025
-
5.4
MEDIUMCVE-2023-26950
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Title parameter under the Adding Categories module.... Read more
Affected Products : onekeyadmin- EPSS Score: %0.08
- Published: Mar. 08, 2023
- Modified: Mar. 05, 2025
-
5.4
MEDIUMCVE-2020-2173
Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports served by the plugin, resulting in an XSS vulnerability exploitable by users able to change report content.... Read more
Affected Products : gatling- EPSS Score: %0.16
- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-36405
Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in amCharts: Charts and Maps plugin <= 1.4 at WordPress.... Read more
Affected Products : amcharts\- EPSS Score: %0.29
- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-36432
The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers to perform Cross-site Scripting attacks on admin panel users by manipulating the generated preview application response.... Read more
Affected Products : blog_pro- EPSS Score: %0.19
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2019-4470
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust... Read more
Affected Products : qradar_security_information_and_event_manager- EPSS Score: %0.24
- Published: Nov. 09, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4486
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted... Read more
- EPSS Score: %0.21
- Published: Oct. 24, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-42115
Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.36 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the object field's `Labe... Read more
Affected Products : liferay_portal- EPSS Score: %0.19
- Published: Oct. 18, 2022
- Modified: May. 13, 2025
-
5.4
MEDIUMCVE-2022-4219
The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the manage() function. This makes it possible for unauthenticated attackers to delete s... Read more
Affected Products : chained_quiz- EPSS Score: %0.08
- Published: Dec. 02, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-3005
A vulnerability was found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this issue is some unknown functionality of the component Friend Link Handler. The manipulation leads to cross site scripting. The attack may be launc... Read more
Affected Products : forestblog- Published: Mar. 31, 2025
- Modified: Jun. 12, 2025
-
5.4
MEDIUMCVE-2022-37244
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to inject malicious tag leads to IFRAME injection.... Read more
Affected Products : security_gateway_for_email_servers- EPSS Score: %0.66
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2236
Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Run/Update permission.... Read more
Affected Products : yet_another_build_visualizer- EPSS Score: %0.23
- Published: Aug. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2243
Jenkins Cadence vManager Plugin 3.0.4 and earlier does not escape build descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.... Read more
Affected Products : cadence_vmanager- EPSS Score: %0.23
- Published: Sep. 01, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-42954
Keyfactor EJBCA before 7.10.0 allows XSS.... Read more
Affected Products : kefactor_ejbca- EPSS Score: %0.77
- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025