Latest CVE Feed
-
5.4
MEDIUMCVE-2022-38089
Stored cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote auth... Read more
- EPSS Score: %0.44
- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-23214
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Configure categories" field under the "Categorise Lists" module.... Read more
Affected Products : phplist- EPSS Score: %0.26
- Published: Jul. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4353
A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this vulnerability is the function IpUtil.getIpAddr. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has b... Read more
Affected Products : pb-cms- EPSS Score: %0.06
- Published: Dec. 08, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-23656
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Content."... Read more
Affected Products : navigatecms- EPSS Score: %0.21
- Published: Aug. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-44590
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in James Lao's Simple Video Embedder plugin <= 2.2 on WordPress.... Read more
Affected Products : simple_video_embedder- EPSS Score: %0.14
- Published: Nov. 09, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4718
IBM Jazz for Service Management 3.13 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr... Read more
Affected Products : jazz_for_service_management- EPSS Score: %0.16
- Published: Mar. 23, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4468
The WP Recipe Maker WordPress plugin before 8.6.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attac... Read more
Affected Products : wp_recipe_maker- EPSS Score: %0.14
- Published: Jan. 09, 2023
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2022-4474
The Easy Social Feed WordPress plugin before 6.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting atta... Read more
Affected Products : easy_social_feed- EPSS Score: %0.10
- Published: Jan. 23, 2023
- Modified: Apr. 02, 2025
-
5.4
MEDIUMCVE-2022-3986
The WP Stripe Checkout WordPress plugin before 1.2.2.21 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting... Read more
Affected Products : wp_stripe_checkout- EPSS Score: %0.10
- Published: Dec. 19, 2022
- Modified: Apr. 17, 2025
-
5.4
MEDIUMCVE-2019-4747
IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.... Read more
- EPSS Score: %0.18
- Published: Jul. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-2954
Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master.... Read more
Affected Products : djangoblog- EPSS Score: %0.11
- Published: May. 29, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-4887
The Joint Radio Blues (aka com.nobexinc.wls_69685189.rc) application 3.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificat... Read more
Affected Products : joint_radio_blues- EPSS Score: %0.04
- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-4486
The Meteor Slides WordPress plugin before 1.5.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : meteor_slides- EPSS Score: %0.14
- Published: Jan. 16, 2023
- Modified: Apr. 07, 2025
-
5.4
MEDIUMCVE-2022-44953
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /linkedcontent/listfiles.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name f... Read more
Affected Products : webtareas- EPSS Score: %0.08
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2023-29847
AeroCMS v0.0.1 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the comment_author and comment_content parameters at /post.php. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via a cr... Read more
Affected Products : aerocms- EPSS Score: %0.08
- Published: Apr. 14, 2023
- Modified: Feb. 06, 2025
-
5.4
MEDIUMCVE-2022-40191
Authenticated (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Ali Khallad's Contact Form By Mega Forms plugin <= 1.2.4 at WordPress.... Read more
Affected Products : contact_form_by_mega_forms- EPSS Score: %0.28
- Published: Sep. 09, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-45363
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) in Muffingroup Betheme theme <= 26.6.1 on WordPress.... Read more
Affected Products : betheme- EPSS Score: %0.14
- Published: Nov. 22, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4058
The Photo Gallery by 10Web WordPress plugin before 1.8.3 does not validate and escape some parameters before outputting them back in in JS code later on in another page, which could lead to Stored XSS issue when an attacker makes a logged in admin open a ... Read more
Affected Products : photo_gallery- EPSS Score: %0.10
- Published: Dec. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29433
Authenticated (contributor or higher role) Cross-Site Scripting (XSS) vulnerability in Donations plugin <= 1.8 on WordPress.... Read more
Affected Products : donations- EPSS Score: %0.17
- Published: May. 13, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-40963
Multiple Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerabilities in WP Page Builder plugin <= 1.2.6 on WordPress.... Read more
Affected Products : wp_page_builder- EPSS Score: %0.10
- Published: Nov. 18, 2022
- Modified: Nov. 21, 2024