Latest CVE Feed
-
5.4
MEDIUMCVE-2020-23065
Cross Site Scripting vulnerabiltiy in eZ Systems AS eZPublish Platform v.5.4 and eZ Publish Legacy v.5.4 allows a remote authenticated attacker to execute arbitrary code via the video-js.swf.... Read more
- Published: Jun. 26, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-26765
Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Distance Based Shipping Calculator: from n/a through 2.0.22.... Read more
Affected Products :- Published: Feb. 16, 2025
- Modified: Feb. 16, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2023-32536
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authenticat... Read more
Affected Products : apex_central- Published: Jun. 26, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-32604
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authenticat... Read more
Affected Products : apex_central- Published: Jun. 26, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-26274
IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.... Read more
- Published: Jun. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-34837
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a vulnerable parameter GrpPath.... Read more
Affected Products : escan_management_console- Published: Jun. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-3331
Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N... Read more
- Published: Jun. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-51330
PHPJabbers Cinema Booking System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Now Showing menu "date" parameter.... Read more
Affected Products : cinema_booking_system- Published: Feb. 20, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-51337
PHPJabbers Event Ticketing System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in "lid" parameter in index.... Read more
Affected Products : event_ticketing_system- Published: Feb. 20, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-36223
Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary code via a crafted payload to the announcements parameter in the settings function.... Read more
Affected Products : bbs-go- Published: Jul. 03, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-30322
Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/chatWindow.java in Payatu ChatEngine v.1.0, allows attackers to execute arbitrary code.... Read more
Affected Products : chatengine- Published: Jul. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-37122
A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Settings module.... Read more
Affected Products : bagecms- Published: Jul. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-37133
A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : eyoucms- Published: Jul. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-3538
A vulnerability classified as problematic was found in SimplePHPscripts Photo Gallery PHP 2.0. This vulnerability affects unknown code of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The att... Read more
Affected Products : photo_gallery_php- Published: Jul. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-29998
A Cross-site scripting (XSS) vulnerability in the content editor in Gis3W g3w-suite 3.5 allows remote authenticated users to inject arbitrary web script or HTML and gain privileges via the description parameter.... Read more
Affected Products : g3w-suite- Published: Jul. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-2964
The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attribute's content, which may allow users whose role is at least that of a contributor to conduct Stored Cross-Site Scripting attacks.... Read more
Affected Products : simple_iframe- Published: Jul. 10, 2023
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2023-37658
fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS... Read more
Affected Products : fast-poster- Published: Jul. 11, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- Published: Jul. 11, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-38350
PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26.... Read more
Affected Products : pnp4nagios- Published: Jul. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-25916
wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php.... Read more
Affected Products : wuzhicms- Published: Feb. 28, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting