Latest CVE Feed
-
5.4
MEDIUMCVE-2020-23214
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Configure categories" field under the "Categorise Lists" module.... Read more
Affected Products : phplist- Published: Jul. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-23656
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Content."... Read more
Affected Products : navigatecms- Published: Aug. 26, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4718
IBM Jazz for Service Management 3.13 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr... Read more
Affected Products : jazz_for_service_management- Published: Mar. 23, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4468
The WP Recipe Maker WordPress plugin before 8.6.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attac... Read more
Affected Products : wp_recipe_maker- Published: Jan. 09, 2023
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2022-4486
The Meteor Slides WordPress plugin before 1.5.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : meteor_slides- Published: Jan. 16, 2023
- Modified: Apr. 07, 2025
-
5.4
MEDIUMCVE-2022-44953
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /linkedcontent/listfiles.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name f... Read more
Affected Products : webtareas- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2023-29847
AeroCMS v0.0.1 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the comment_author and comment_content parameters at /post.php. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via a cr... Read more
Affected Products : aerocms- Published: Apr. 14, 2023
- Modified: Feb. 06, 2025
-
5.4
MEDIUMCVE-2022-40191
Authenticated (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Ali Khallad's Contact Form By Mega Forms plugin <= 1.2.4 at WordPress.... Read more
Affected Products : contact_form_by_mega_forms- Published: Sep. 09, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-45363
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) in Muffingroup Betheme theme <= 26.6.1 on WordPress.... Read more
Affected Products : betheme- Published: Nov. 22, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4058
The Photo Gallery by 10Web WordPress plugin before 1.8.3 does not validate and escape some parameters before outputting them back in in JS code later on in another page, which could lead to Stored XSS issue when an attacker makes a logged in admin open a ... Read more
Affected Products : photo_gallery- Published: Dec. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29433
Authenticated (contributor or higher role) Cross-Site Scripting (XSS) vulnerability in Donations plugin <= 1.8 on WordPress.... Read more
Affected Products : donations- Published: May. 13, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-40963
Multiple Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerabilities in WP Page Builder plugin <= 1.2.6 on WordPress.... Read more
Affected Products : wp_page_builder- Published: Nov. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-30789
MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/work` endpoint and job and company parameter.... Read more
Affected Products : monica- Published: May. 08, 2023
- Modified: Feb. 03, 2025
-
5.4
MEDIUMCVE-2022-41139
MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary commands on agents.... Read more
- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
5.4
MEDIUMCVE-2022-4653
The Greenshift WordPress plugin before 4.8.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more
- Published: Jan. 16, 2023
- Modified: Jun. 10, 2025
-
5.4
MEDIUMCVE-2022-4677
The Leaflet Maps Marker WordPress plugin before 3.12.7 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more
Affected Products : leaflet_maps_marker- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2023-31862
jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is only filtered in the front end, without being filtered in the background, which allows attackers to publish an article containing malicio... Read more
Affected Products : jizhicms- Published: May. 19, 2023
- Modified: Jan. 21, 2025
-
5.4
MEDIUMCVE-2020-24670
The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'type' ... Read more
Affected Products : vantara_pentaho- Published: Jan. 29, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-47073
A cross-site scripting (XSS) vulnerability in the Create Ticket page of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject parameter.... Read more
- Published: Jan. 26, 2023
- Modified: Apr. 01, 2025
-
5.4
MEDIUMCVE-2022-48177
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Import Records Model field (model parameter). This vulnerability allows attackers to create malicious JavaScri... Read more
Affected Products : x2crm- Published: Apr. 15, 2023
- Modified: Feb. 06, 2025