Latest CVE Feed
-
5.4
MEDIUMCVE-2024-45528
CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.... Read more
Affected Products : membership_management_system- Published: Sep. 02, 2024
- Modified: Mar. 31, 2025
-
5.4
MEDIUMCVE-2023-26842
A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the OptionManager.php.... Read more
Affected Products : churchcrm- Published: May. 31, 2023
- Modified: Jan. 09, 2025
-
5.4
MEDIUMCVE-2023-43710
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "configuration_title[1][MODULE_SHIPPING_PERCENT_TEXT_TITLE]" parameter, potentially leading to unauthorized ex... Read more
Affected Products : oscommerce- Published: Sep. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43703
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "product_info[][name]" parameter, potentially leading to unauthorized execution of scripts within a user's web... Read more
Affected Products : oscommerce- Published: Sep. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43724
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "derb6zmklgtjuhh2cn5chn2qjbm2stgmfa4.oastify.comscription[1][name]" parameter, potentially leading to unauthor... Read more
Affected Products : oscommerce- Published: Sep. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-38970
Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the Name of member parameter in the add new member function.... Read more
Affected Products : badaso- Published: Aug. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-38991
An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete models created by the Administrator.... Read more
Affected Products : jeesite- Published: Aug. 04, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43990
An issue in cherub-hair mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 24, 2024
- Modified: May. 30, 2025
-
5.4
MEDIUMCVE-2024-4732
A vulnerability, which was classified as problematic, has been found in Campcodes Legal Case Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/service. The manipulation of the argument name leads to cross site ... Read more
Affected Products : legal_case_management_system- Published: May. 14, 2024
- Modified: Feb. 19, 2025
-
5.4
MEDIUMCVE-2021-41866
MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.... Read more
Affected Products : mybb- Published: Oct. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-44276
OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.... Read more
Affected Products : opnsense- Published: Sep. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-50983
FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with administrative rights to inject arbitrary JavaScript in the web browser of a user by including a malicious payload into the Last Name sect... Read more
Affected Products : flightpath- Published: Nov. 15, 2024
- Modified: Jul. 07, 2025
-
5.4
MEDIUMCVE-2024-2121
The Elementor Website Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Media Carousel widget in all versions up to, and including, 3.20.1 due to insufficient input sanitization and output escaping on user supp... Read more
- Published: Mar. 27, 2024
- Modified: Mar. 12, 2025
-
5.4
MEDIUMCVE-2024-52584
Autolab is a course management service that enables auto-graded programming assignments. There is a vulnerability in version 3.0.1 where CAs can view or edit the grade for any submission ID, even if they are not a CA for the class that has the submission.... Read more
Affected Products : autolab- Published: Nov. 18, 2024
- Modified: Jan. 21, 2025
-
5.4
MEDIUMCVE-2024-52944
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting while viewing archived content. This could r... Read more
Affected Products : enterprise_vault- Published: Nov. 18, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2023-45806
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, if a user has been quoted and uses a `|` in their full name, they might be able... Read more
Affected Products : discourse- Published: Nov. 10, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10051
iScripts SupportDesk v4.3 has XSS via the staff/inteligentsearchresult.php txtinteligentsearch parameter.... Read more
Affected Products : supportdesk- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-40705
Stored cross-site scripting vulnerability in Map setting page of VI Web Client prior to 7.9.6 allows a remote authenticated attacker to inject an arbitrary script.... Read more
Affected Products : video_insight- Published: Sep. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-45998
kodbox 1.44 is vulnerable to Cross Site Scripting (XSS). Customizing global HTML results in storing XSS.... Read more
Affected Products : kodbox- Published: Oct. 23, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-33910
An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers to attach crafted SVG documents to issue reports or bugnotes. When a user or an admin clicks on the attachment, file_download.php opens the SVG document in a browser tab instead of dow... Read more
Affected Products : mantisbt- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024