Latest CVE Feed
-
5.4
MEDIUMCVE-2022-31048
TYPO3 is an open source web content management system. Prior to versions 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, the Form Designer backend module of the Form Framework is vulnerable to cross-site scripting. A valid backend user account with access... Read more
Affected Products : typo3- Published: Jun. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5791
The Daum Cloud (aka net.daum.android.cloud) application 1.6.18 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : daum_cloud- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2022-31128
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versions Tuleap does not properly verify permissions when creating branches with the REST API in Git repositories using the fine grained per... Read more
Affected Products : tuleap- Published: Aug. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-32167
Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to privilege escalation.... Read more
Affected Products : cloudreve- Published: Sep. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-32567
The Appfire Jira Misc Custom Fields (JMCF) app 2.4.6 for Atlassian Jira allows XSS via a crafted project name to the Add Auto Indexing Rule function.... Read more
Affected Products : jira_misc_custom_fields- Published: Jul. 07, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-32750
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering ... Read more
Affected Products : datapower_gateway- Published: Aug. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-23984
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu plugin <= 3.0.1 leading to form deletion.... Read more
Affected Products : bubble_menu- Published: Mar. 01, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3497
A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been classified as problematic. Affected is an unknown function of the component Master List. The manipulation of the argument city/state/country/position leads to cr... Read more
Affected Products : human_resource_management_system- Published: Oct. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3503
A vulnerability was found in SourceCodester Purchase Order Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the component Supplier Handler. The manipulation of the argument Supplier Name/Address/Contac... Read more
Affected Products : purchase_order_management_system- Published: Oct. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-19090
tianti 2.3 has stored XSS in the article management module via an article title.... Read more
Affected Products : tianti- Published: Nov. 07, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20683
Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.... Read more
Affected Products : basercms- Published: Mar. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-26847
A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the state parameter at opencats/index.php?m=candidates.... Read more
Affected Products : opencats- Published: Apr. 11, 2023
- Modified: Feb. 11, 2025
-
5.4
MEDIUMCVE-2020-2173
Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports served by the plugin, resulting in an XSS vulnerability exploitable by users able to change report content.... Read more
Affected Products : gatling- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-36432
The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers to perform Cross-site Scripting attacks on admin panel users by manipulating the generated preview application response.... Read more
Affected Products : blog_pro- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2022-4219
The Chained Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.2.4. This is due to missing nonce validation on the manage() function. This makes it possible for unauthenticated attackers to delete s... Read more
Affected Products : chained_quiz- Published: Dec. 02, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2236
Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Run/Update permission.... Read more
Affected Products : yet_another_build_visualizer- Published: Aug. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-42954
Keyfactor EJBCA before 7.10.0 allows XSS.... Read more
Affected Products : kefactor_ejbca- Published: Nov. 17, 2022
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2022-38089
Stored cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote auth... Read more
- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-23214
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Configure categories" field under the "Categorise Lists" module.... Read more
Affected Products : phplist- Published: Jul. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-23656
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Content."... Read more
Affected Products : navigatecms- Published: Aug. 26, 2020
- Modified: Nov. 21, 2024