Latest CVE Feed
-
5.4
MEDIUMCVE-2018-16637
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.... Read more
Affected Products : evolution_cms- Published: Dec. 28, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-27371
The Contact page in Monica 2.19.1 allows stored XSS via the Description field.... Read more
Affected Products : monica- Published: Feb. 22, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-27658
exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.... Read more
Affected Products : exacqvision_enterprise_manager- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-28380
The aimeos (aka Aimeos shop and e-commerce framework) extension before 19.10.12 and 20.x before 20.10.5 for TYPO3 allows XSS via a backend user account.... Read more
Affected Products : aimeos- Published: Mar. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-30039
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-report.php.... Read more
Affected Products : remote_clinic- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-31329
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php... Read more
Affected Products : remote_clinic- Published: Apr. 21, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-31583
Sipwise C5 NGCP WWW Admin version 3.6.7 up to and including platform version NGCP CE 3.0 has multiple authenticated stored and reflected XSS vulnerabilities when input passed via several parameters to several scripts is not properly sanitized before being... Read more
Affected Products : next_generation_communication_platform- Published: Apr. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-24588
Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function.... Read more
Affected Products : flatpress- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-3224
A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter.... Read more
Affected Products : csz_cms- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-5280
SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.... Read more
- Published: Jan. 08, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38713
imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header.... Read more
Affected Products : imgurl- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-38822
A Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that allows for arbitrary execution of JavaScript commands.... Read more
Affected Products : icehrm- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-33295
Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code due to improper sanitizing of html.... Read more
Affected Products : joplin- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-39079
IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadi... Read more
Affected Products : cognos_analytics_mobile- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-39486
A Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, passwords or to run arbitrary code on a victim's browser.... Read more
Affected Products : gila_cms- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-26555
A stored cross-site scripting (XSS) vulnerability in the Add a Button function of Eova v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the button name text box.... Read more
Affected Products : eova- Published: Mar. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-2689
A vulnerability classified as problematic has been found in SourceCodester Wedding Hall Booking System. Affected is an unknown function of the file /whbs/?page=contact_us of the component Contact Page. The manipulation of the argument Message leads to cro... Read more
Affected Products : wedding_hall_booking_system- Published: Aug. 06, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-28448
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.... Read more
Affected Products : nopcommerce- Published: Apr. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-41948
A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List of subjects".... Read more
Affected Products : subrion- Published: Apr. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-18373
In the Schiocco "Support Board - Chat And Help Desk" plugin 1.2.3 for WordPress, a Stored XSS vulnerability has been discovered in file upload areas in the Chat and Help Desk sections via the msg parameter in a /wp-admin/admin-ajax.php sb_ajax_add_message... Read more
- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024