Latest CVE Feed
-
5.4
MEDIUMCVE-2020-10935
Zulip Server before 2.1.3 allows XSS via a Markdown link, with resultant account takeover.... Read more
Affected Products : zulip_server- Published: Apr. 20, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0168
The Olevmedia Shortcodes WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to p... Read more
Affected Products : olevmedia_shortcodes- Published: Feb. 27, 2023
- Modified: Mar. 18, 2025
-
5.4
MEDIUMCVE-2023-0176
The Giveaways and Contests by RafflePress WordPress plugin before 1.11.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor ro... Read more
- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2021-24439
The Browser Screenshots WordPress plugin before 1.7.6 allowed authenticated users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks as the image_class parameter of the browser-shot shortcode was not escaped.... Read more
Affected Products : browser_screenshots- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0272
The NEX-Forms WordPress plugin before 8.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Store... Read more
Affected Products : nex-forms- Published: Mar. 27, 2023
- Modified: Feb. 19, 2025
-
5.4
MEDIUMCVE-2021-24548
The Mimetic Books WordPress plugin through 0.2.13 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) in the "Default Publisher ID" field on the plugin's settings page.... Read more
Affected Products : mimetic_books- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-3938
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : snipe-it- Published: Nov. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0368
The Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow ... Read more
Affected Products : responsive_tabs_for_wpbakery_page_builder- Published: Jun. 19, 2023
- Modified: Dec. 12, 2024
-
5.4
MEDIUMCVE-2019-13931
A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow for an an attacker to craft the input in a form that is not expected, causing the application to behave in unexpected ways for legitimate users. Successful... Read more
Affected Products : xhq- Published: Dec. 12, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24308
The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of the profile page, leading t... Read more
Affected Products : lifterlms- Published: May. 24, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-35629
Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own client ID, to send messages to the server claiming to come from another client ID. This issue was resolved i... Read more
Affected Products : velociraptor- Published: Jul. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-35199
NETSCOUT nGeniusONE 6.3.0 build 1196 and earlier allows Stored Cross-Site Scripting (XSS) in UploadFile.... Read more
Affected Products : ngeniusone- Published: Sep. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0542
The Custom Post Type List Shortcode WordPress plugin through 1.4.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and... Read more
Affected Products : custom_post_type_list_shortcode- Published: May. 08, 2023
- Modified: Feb. 04, 2025
-
5.4
MEDIUMCVE-2023-0546
The Contact Form Plugin WordPress plugin before 4.3.25 does not properly sanitize and escape the srcdoc attribute in iframes in it's custom HTML field type, allowing a logged in user with roles as low as contributor to inject arbitrary javascript into a f... Read more
- Published: Apr. 10, 2023
- Modified: Feb. 11, 2025
-
5.4
MEDIUMCVE-2024-50573
In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services... Read more
Affected Products : hub- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
5.4
MEDIUMCVE-2024-46606
A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.... Read more
Affected Products : piwigo- Published: Oct. 16, 2024
- Modified: May. 22, 2025
-
5.4
MEDIUMCVE-2024-50840
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the class_name parameter.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: May. 06, 2025
-
5.4
MEDIUMCVE-2023-43730
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "countries_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web br... Read more
Affected Products : oscommerce- Published: Sep. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-35959
In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a folder with a SCRIPT tag in the description field.... Read more
Affected Products : plone- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48838
Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.... Read more
Affected Products : appointment_scheduler- Published: Dec. 07, 2023
- Modified: Nov. 21, 2024