Latest CVE Feed
-
5.4
MEDIUMCVE-2023-3970
A vulnerability, which was classified as problematic, was found in GZ Scripts Availability Booking Calendar PHP 1.0. This affects an unknown part of the file /index.php?controller=GzUser&action=edit&id=1 of the component Image Handler. The manipulation of... Read more
Affected Products : availability_booking_calendar_php- EPSS Score: %0.07
- Published: Jul. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-25879
A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Username' parameter.... Read more
Affected Products : codoforum- EPSS Score: %0.16
- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0173
The Drag & Drop Sales Funnel Builder for WordPress plugin before 2.6.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role... Read more
Affected Products : drag_\&_drop_sales_funnel_builder- EPSS Score: %0.25
- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2023-0369
The GoToWP WordPress plugin through 5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored ... Read more
Affected Products : gotowp- EPSS Score: %0.12
- Published: Mar. 20, 2023
- Modified: Feb. 26, 2025
-
5.4
MEDIUMCVE-2023-21523
A Stored Cross-site Scripting (XSS) vulnerability in the Management Console (User Management and Alerts) of BlackBerry AtHoc version 7.15 could allow an attacker to execute script commands in the context of the affected user account... Read more
Affected Products : athoc- EPSS Score: %0.47
- Published: Sep. 12, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0403
The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.0. This is due to missing or incorrect nonce validation on several AJAX actions. This makes it possible for unauthenticated attackers... Read more
Affected Products : social_warfare- EPSS Score: %0.06
- Published: Jan. 19, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-38303
An issue was discovered in Webmin 2.021. One can exploit a stored Cross-Site Scripting (XSS) attack to achieve Remote Command Execution (RCE) through the Users and Group's real name parameter.... Read more
Affected Products : webmin- EPSS Score: %0.16
- Published: Jul. 31, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1245
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.... Read more
Affected Products : answer- EPSS Score: %0.09
- Published: Mar. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-22425
Stored cross-site scripting vulnerability in Schedule function of SHIRASAGI v1.16.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script.... Read more
Affected Products : shirasagi- EPSS Score: %0.32
- Published: Feb. 24, 2023
- Modified: Mar. 12, 2025
-
5.4
MEDIUMCVE-2023-42817
Pimcore admin-ui-classic-bundle provides a Backend UI for Pimcore. The translation value with text including “%s” (from “%suggest%) is parsed by sprintf() even though it’s supposed to be output literally to the user. The translations may be accessible by ... Read more
Affected Products : admin_classic_bundle- EPSS Score: %0.00
- Published: Sep. 25, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0695
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'mf' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authenticated attackers, with contributor-le... Read more
Affected Products : metform_elementor_contact_form_builder- EPSS Score: %0.08
- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43458
Cross Site Scripting (XSS) vulnerability in Resort Reservation System v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the room, name, and description parameters in the manage_room function.... Read more
- EPSS Score: %0.34
- Published: Sep. 25, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-26669
A stored cross-site scripting (XSS) vulnerability was discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary web scripts or HTML via the page content to site/index.php/admin/pages/update.... Read more
Affected Products : bigtree_cms- EPSS Score: %0.21
- Published: Jun. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15036
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Topology-Linked.php dv parameter.... Read more
Affected Products : nedi- EPSS Score: %0.21
- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43707
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "CatalogsPageDescriptionForm[1][name] " parameter, potentially leading to unauthorized execution of scripts wi... Read more
Affected Products : oscommerce- EPSS Score: %0.10
- Published: Sep. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-20132
Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack or upload arbitrary files as recordings. For more information about these vulnerabili... Read more
Affected Products : webex_meetings- EPSS Score: %0.13
- Published: Apr. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5925
The 10000 Kindle Books Downloads (aka com.ww10000KindleBooksLatestnBestSellers) application 0.312 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information v... Read more
Affected Products : 10000_kindle_books_downloads- EPSS Score: %0.04
- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5929
The emartmall (aka kr.co.emart.emartmall) application 1.3.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : emartmall- EPSS Score: %0.04
- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-43992
An issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- EPSS Score: %0.08
- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2023-2415
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This ... Read more
- EPSS Score: %0.03
- Published: Jun. 03, 2023
- Modified: Jun. 10, 2025