Latest CVE Feed
-
5.4
MEDIUMCVE-2020-24860
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.... Read more
Affected Products : cms_made_simple- EPSS Score: %0.63
- Published: Oct. 01, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-48177
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Import Records Model field (model parameter). This vulnerability allows attackers to create malicious JavaScri... Read more
Affected Products : x2crm- EPSS Score: %1.49
- Published: Apr. 15, 2023
- Modified: Feb. 06, 2025
-
5.4
MEDIUMCVE-2020-13892
The SportsPress plugin before 2.7.2 for WordPress allows XSS.... Read more
Affected Products : sportspress- EPSS Score: %0.16
- Published: Jun. 09, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-24924
A Persistent Cross-site Scripting vulnerability is found in ElkarBackup v1.3.3, where an attacker can steal the user session cookie using this vulnerability present on Policies >> action >> Name Parameter... Read more
Affected Products : elkarbackup- EPSS Score: %0.26
- Published: Sep. 15, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4864
Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.... Read more
Affected Products : froxlor- EPSS Score: %0.07
- Published: Dec. 30, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4306
The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permiss... Read more
Affected Products : panda_pods_repeater_field- EPSS Score: %8.28
- Published: Jan. 30, 2023
- Modified: Mar. 27, 2025
-
5.4
MEDIUMCVE-2022-43144
A cross-site scripting (XSS) vulnerability in Canteen Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : canteen_management_system- EPSS Score: %0.94
- Published: Nov. 08, 2022
- Modified: May. 01, 2025
-
5.4
MEDIUMCVE-2020-18693
Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious code into the 'Title' field of the component '/admin/news'.... Read more
Affected Products : minewebcms- EPSS Score: %0.26
- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-43491
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.5 on WordPress leading to plugin settings import.... Read more
Affected Products : advanced_dynamic_pricing_for_woocommerce- EPSS Score: %0.08
- Published: Nov. 08, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-43499
Stored cross-site scripting vulnerability in SHIRASAGI versions prior to v1.16.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.... Read more
Affected Products : shirasagi- EPSS Score: %0.29
- Published: Dec. 05, 2022
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2022-4377
A vulnerability was found in S-CMS 5.0 Build 20220328. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Contact Information Page. The manipulation of the argument Make a Call leads to cross s... Read more
Affected Products : s-cms- EPSS Score: %0.09
- Published: Dec. 09, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4381
The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : popup_maker- EPSS Score: %0.14
- Published: Jan. 02, 2023
- Modified: Apr. 10, 2025
-
5.4
MEDIUMCVE-2020-14012
scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent.... Read more
Affected Products : osticket- EPSS Score: %0.19
- Published: Jun. 10, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-43952
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC version 7.1.1 and below, version 7.0.3 and below, version 6.2.5 and below may allow an authenticated attacker to perform a cross-sit... Read more
Affected Products : fortiadc- EPSS Score: %0.25
- Published: Apr. 11, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-33751
A stored cross-site scripting (XSS) vulnerability in mipjz v5.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at /app/tag/controller/ApiAdminTagCategory.php.... Read more
Affected Products : mipjz- EPSS Score: %0.08
- Published: May. 25, 2023
- Modified: Jan. 31, 2025
-
5.4
MEDIUMCVE-2022-4487
The Easy Accordion WordPress plugin before 2.2.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack... Read more
Affected Products : easy_accordion- EPSS Score: %0.14
- Published: Jan. 16, 2023
- Modified: Apr. 08, 2025
-
5.4
MEDIUMCVE-2022-44944
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or H... Read more
Affected Products : rukovoditel- EPSS Score: %1.10
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2022-44951
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at /index.php?module=entities/forms&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTM... Read more
Affected Products : rukovoditel- EPSS Score: %1.73
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2022-44954
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /contacts/listcontacts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Nam... Read more
Affected Products : webtareas- EPSS Score: %0.08
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2023-34439
Pleasanter 1.3.47.0 and earlier contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web browser.... Read more
Affected Products : pleasanter- EPSS Score: %0.49
- Published: Dec. 06, 2023
- Modified: Nov. 21, 2024