Latest CVE Feed
-
5.4
MEDIUMCVE-2023-31862
jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is only filtered in the front end, without being filtered in the background, which allows attackers to publish an article containing malicio... Read more
Affected Products : jizhicms- Published: May. 19, 2023
- Modified: Jan. 21, 2025
-
5.4
MEDIUMCVE-2020-24670
The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code. Specifically, the vulnerability lies in the 'type' ... Read more
Affected Products : vantara_pentaho- Published: Jan. 29, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-47073
A cross-site scripting (XSS) vulnerability in the Create Ticket page of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject parameter.... Read more
- Published: Jan. 26, 2023
- Modified: Apr. 01, 2025
-
5.4
MEDIUMCVE-2022-48177
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Import Records Model field (model parameter). This vulnerability allows attackers to create malicious JavaScri... Read more
Affected Products : x2crm- Published: Apr. 15, 2023
- Modified: Feb. 06, 2025
-
5.4
MEDIUMCVE-2022-4864
Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.... Read more
Affected Products : froxlor- Published: Dec. 30, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4306
The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permiss... Read more
Affected Products : panda_pods_repeater_field- Published: Jan. 30, 2023
- Modified: Mar. 27, 2025
-
5.4
MEDIUMCVE-2022-43491
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.5 on WordPress leading to plugin settings import.... Read more
Affected Products : advanced_dynamic_pricing_for_woocommerce- Published: Nov. 08, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-33751
A stored cross-site scripting (XSS) vulnerability in mipjz v5.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at /app/tag/controller/ApiAdminTagCategory.php.... Read more
Affected Products : mipjz- Published: May. 25, 2023
- Modified: Jan. 31, 2025
-
5.4
MEDIUMCVE-2022-4487
The Easy Accordion WordPress plugin before 2.2.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack... Read more
Affected Products : easy_accordion- Published: Jan. 16, 2023
- Modified: Apr. 08, 2025
-
5.4
MEDIUMCVE-2022-44951
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at /index.php?module=entities/forms&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTM... Read more
Affected Products : rukovoditel- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2022-44954
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /contacts/listcontacts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Nam... Read more
Affected Products : webtareas- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2023-34439
Pleasanter 1.3.47.0 and earlier contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web browser.... Read more
Affected Products : pleasanter- Published: Dec. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4958
A vulnerability classified as problematic has been found in qkmc-rk redbbs 1.0. Affected is an unknown function of the component Post Handler. The manipulation of the argument title leads to cross site scripting. It is possible to launch the attack remote... Read more
Affected Products : redbbs- Published: Jan. 11, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4642
A vulnerability was found in tatoeba2. It has been classified as problematic. This affects an unknown part of the component Profile Name Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit h... Read more
Affected Products : tatoeba2- Published: Dec. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4674
The Ibtana WordPress plugin before 1.1.8.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack... Read more
Affected Products : ibtana- Published: Feb. 06, 2023
- Modified: Mar. 26, 2025
-
5.4
MEDIUMCVE-2022-4675
The Mongoose Page Plugin WordPress plugin before 1.9.0 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more
Affected Products : mongoose_page_plugin- Published: Jan. 23, 2023
- Modified: Apr. 02, 2025
-
5.4
MEDIUMCVE-2023-0287
A vulnerability was found in ityouknow favorites-web. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Comment Handler. The manipulation leads to cross site scripting. The attack may be launched remot... Read more
Affected Products : favorites-web- Published: Jan. 13, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0370
The WPB Advanced FAQ WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perfo... Read more
Affected Products : wpb_advanced_faq- Published: Mar. 20, 2023
- Modified: Feb. 26, 2025
-
5.4
MEDIUMCVE-2021-42329
The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title parameter. After logging in with user’s privilege, remote attackers can inject JavaScript and execute stored XSS attacks.... Read more
Affected Products : xinhe_teaching_platform_system- Published: Oct. 15, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-47524
F-Secure SAFE Browser 19.1 before 19.2 for Android allows an IDN homograph attack.... Read more
Affected Products : safe- Published: Dec. 23, 2022
- Modified: Apr. 15, 2025