Latest CVE Feed
-
5.4
MEDIUMCVE-2023-0231
The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Si... Read more
Affected Products : shoplentor- EPSS Score: %0.15
- Published: Feb. 21, 2023
- Modified: Mar. 12, 2025
-
5.4
MEDIUMCVE-2023-3653
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital Ant E-Commerce Software allows Stored XSS.This issue affects E-Commerce Software: before 11. ... Read more
Affected Products : digital_ant- EPSS Score: %0.08
- Published: Aug. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0276
The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and abov... Read more
Affected Products : weaver_xtreme_theme_support- EPSS Score: %0.09
- Published: Apr. 24, 2023
- Modified: Feb. 04, 2025
-
5.4
MEDIUMCVE-2023-0167
The GetResponse for WordPress plugin through 5.5.31 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perfo... Read more
Affected Products : getresponse- EPSS Score: %0.14
- Published: Mar. 20, 2023
- Modified: Feb. 26, 2025
-
5.4
MEDIUMCVE-2022-46870
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers. This issue affects Apache Zeppelin before 0.8.2. User... Read more
Affected Products : zeppelin- EPSS Score: %2.13
- Published: Dec. 16, 2022
- Modified: Apr. 17, 2025
-
5.4
MEDIUMCVE-2022-46906
Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Reflec... Read more
Affected Products : websoft_hcm- EPSS Score: %0.52
- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2022-47102
A cross-site scripting (XSS) vulnerability in Student Study Center Management System V 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.... Read more
- EPSS Score: %0.22
- Published: Jan. 12, 2023
- Modified: Apr. 08, 2025
-
5.4
MEDIUMCVE-2023-0513
A vulnerability has been found in isoftforce Dreamer CMS up to 4.0.1 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclos... Read more
- EPSS Score: %0.29
- Published: Jan. 26, 2023
- Modified: Apr. 04, 2025
-
5.4
MEDIUMCVE-2022-40257
An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field.... Read more
Affected Products : vince- EPSS Score: %0.13
- Published: Oct. 10, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4750
The WP Responsive Testimonials Slider And Widget WordPress plugin through 1.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contribut... Read more
Affected Products : wp_responsive_testimonials_slider_and_widget- EPSS Score: %0.10
- Published: Feb. 21, 2023
- Modified: May. 05, 2025
-
5.4
MEDIUMCVE-2023-0729
The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sort_order function. This makes it possible for unauthenti... Read more
Affected Products : wicked_folders- EPSS Score: %0.09
- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4824
The WP Blog and Widgets WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting a... Read more
Affected Products : wp_blog_and_widget- EPSS Score: %0.37
- Published: Feb. 06, 2023
- Modified: Mar. 26, 2025
-
5.4
MEDIUMCVE-2023-37625
A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Link templates.... Read more
- EPSS Score: %1.63
- Published: Aug. 10, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-3788
A vulnerability, which was classified as problematic, has been found in ActiveITzone Active Super Shop CMS 2.5. This issue affects some unknown processing of the component Manage Details Page. The manipulation of the argument name/phone/address leads to c... Read more
Affected Products : active_super_shop- EPSS Score: %0.10
- Published: Jul. 20, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-19350
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.... Read more
Affected Products : seacms- EPSS Score: %0.21
- Published: Nov. 17, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1609
A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been rated as problematic. This issue affects the function save of the file /api/admin/store/product/save. The manipulation leads to cross site scripting. The attack may be initiated r... Read more
Affected Products : crmeb_java- EPSS Score: %0.06
- Published: Mar. 23, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1746
A vulnerability, which was classified as problematic, was found in Dreamer CMS up to 3.5.0. Affected is an unknown function of the component File Upload Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely.... Read more
- EPSS Score: %0.07
- Published: Mar. 30, 2023
- Modified: Apr. 04, 2025
-
5.4
MEDIUMCVE-2020-25799
LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey quota being viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser.... Read more
Affected Products : limesurvey- EPSS Score: %0.26
- Published: Dec. 31, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-14529
Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Investor Module). Supported versions that are affected are 16.1.0.0-16.1.5.1, 18.0.0.0-18.0.2.0 and 19.0.0.0. Easily exploitable vulnerability a... Read more
Affected Products : primavera_portfolio_management- EPSS Score: %0.18
- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-38304
An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users and Groups functionality, allowing an attacker to store a malicious payload in the Group Name field when creating a new group.... Read more
Affected Products : webmin- EPSS Score: %0.12
- Published: Jul. 31, 2023
- Modified: Nov. 21, 2024