Latest CVE Feed
-
5.4
MEDIUMCVE-2016-0683
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to Search Framework.... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Apr. 21, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2017-3847
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. More Information: CSCvc72741. Known Affected Releas... Read more
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2020-0656
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'.... Read more
Affected Products : dynamics_365- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-14869
PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field in a profile.... Read more
Affected Products : php_template_store_script- Published: Aug. 06, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24365
The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for tables. Each column had a type. The type "Custom Field" allowed to choose an arbitrary database column to display in the table. There was... Read more
Affected Products : admin_columns- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24464
The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site Scripti... Read more
Affected Products : youtube_embed\,_playlist_and_popup- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-44299
A reflected cross-site scripting (XSS) vulnerability in \lib\packages\themes\themes.php of Navigate CMS v2.9.4 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : navigate_cms- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-15190
PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field.... Read more
Affected Products : hotel_booking_script- Published: Aug. 10, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25656
Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0 through 7.2.3 (without hotfix) and... Read more
Affected Products : aura_experience_portal- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20770
Cross-site scripting vulnerability in Message of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.... Read more
Affected Products : garoon- Published: Aug. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-26082
The XML Export in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitrary HTML or JavaScript via a stored cross site scripting vu... Read more
- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-28001
A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiti... Read more
Affected Products : textpattern- Published: Aug. 19, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-15896
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via Personal Address or Company Name.... Read more
Affected Products : website_seller_script- Published: Aug. 28, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0596
Improper Validation of Specified Quantity in Input in Packagist microweber/microweber prior to 1.2.11.... Read more
- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24306
The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not properly sanitise, validate or encode the query string when generating a link to edit user's own profile, leading to an authenticated r... Read more
Affected Products : ultimate_member- Published: May. 24, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24367
The WP Config File Editor WordPress plugin through 1.7.1 was affected by an Authenticated Stored Cross-Site Scripting (XSS) vulnerability.... Read more
Affected Products : wp_config_file_editor- Published: Jun. 21, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24470
The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, leading to a Stored Cross-Site Scripting issue... Read more
Affected Products : yada_wiki- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-29819
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading t... Read more
Affected Products : tivoli_netcool\/omnibus_webgui- Published: Sep. 20, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-16316
A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScript and/or HTML via the Team Name field.... Read more
Affected Products : portainer- Published: Sep. 01, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24634
The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredients, recipeTitle, or settings), which could allow users... Read more
Affected Products : recipe_card_blocks_for_gutenberg_\&_elementor- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024