Latest CVE Feed
-
5.4
MEDIUMCVE-2014-5829
The Hobby Lobby Stores (aka com.hobbylobbystores.android) application 2.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifica... Read more
Affected Products : hobby_lobby_stores- Published: Sep. 09, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2019-4258
IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden... Read more
Affected Products : sterling_b2b_integrator- Published: May. 01, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0200
Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a... Read more
Affected Products : portfolio_post- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-39240
MyGraph is a permission management system. Versions prior to 1.0.4 are vulnerable to a storage XSS vulnerability leading to Remote Code Execution. This issue is patched in version 1.0.4. There is no known workaround.... Read more
Affected Products : mygraph- Published: Sep. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34658
Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.... Read more
- Published: Aug. 23, 2022
- Modified: Mar. 21, 2025
-
5.4
MEDIUMCVE-2023-2553
Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to 2.2.0.... Read more
Affected Products : bumsys- Published: May. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-36106
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the expiration time of a password reset link for TYPO3 backend users has never been evaluated. As a result, a password reset link could... Read more
Affected Products : typo3- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-41789
Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows logged in user with edit permissions to inject arbitrary HTML into the default page header of a wikipage.... Read more
Affected Products : bluespice- Published: Nov. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-2718
The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability.... Read more
Affected Products : contact_form_email- Published: Jun. 12, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-42100
KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location input reply-form.... Read more
Affected Products : klik- Published: Nov. 29, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2022-42200
Simple Exam Reviewer Management System v1.0 is vulnerable to Stored Cross Site Scripting (XSS) via the Exam List.... Read more
Affected Products : simple_exam_reviewer_management_system- Published: Oct. 20, 2022
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2023-2817
A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the... Read more
Affected Products : craft_cms- Published: May. 26, 2023
- Modified: Jan. 15, 2025
-
5.4
MEDIUMCVE-2022-38086
Cross-Site Request Forgery (CSRF) vulnerability in Shortcodes Ultimate plugin <= 5.12.0 at WordPress leading to plugin preset settings change.... Read more
Affected Products : shortcodes_ultimate- Published: Oct. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-42991
A stored cross-site scripting (XSS) vulnerability in Simple Online Public Access Catalog v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Account Full Name field.... Read more
Affected Products : simple_online_public_access_catalog- Published: Oct. 27, 2022
- Modified: May. 07, 2025
-
5.4
MEDIUMCVE-2020-22842
CMS Made Simple before 2.2.15 allows XSS via the m1_mod parameter in a ModuleManager local_uninstall action to admin/moduleinterface.php.... Read more
Affected Products : cms_made_simple- Published: Sep. 30, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-4602
IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosur... Read more
Affected Products : rational_quality_manager- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-23182
The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious websites via a crafted payload entered into the Shoutbox message panel.... Read more
Affected Products : php-fusion- Published: Jul. 02, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-28664
The Meta Data and Taxonomies Filter WordPress plugin, in versions < 1.3.1, is affected by a reflected cross-site scripting vulnerability in the 'tax_name' parameter of the mdf_get_tax_options_in_widget action, which can only be triggered by an authenticat... Read more
Affected Products : wordpress_meta_data_and_taxonomies_filter- Published: Mar. 22, 2023
- Modified: Feb. 25, 2025
-
5.4
MEDIUMCVE-2023-28666
The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'imgurl' parameter to the add_inpost_gallery_slide_item action, which can only be triggered by an authenticated user.... Read more
Affected Products : inpost_gallery- Published: Mar. 22, 2023
- Modified: Feb. 25, 2025
-
5.4
MEDIUMCVE-2022-39027
U-Office Force Forum function has insufficient filtering for special characters. A remote attacker with general user privilege can inject JavaScript and perform XSS (Stored Cross-Site Scripting) attack.... Read more
Affected Products : u-office_force- Published: Oct. 31, 2022
- Modified: Nov. 21, 2024