Latest CVE Feed
-
5.4
MEDIUMCVE-2024-54418
Cross-Site Request Forgery (CSRF) vulnerability in Diversified Technology Corp., WPYog, and Gagan Deep Singh DTC Documents allows Cross Site Request Forgery.This issue affects DTC Documents: from n/a through 1.1.05.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024
-
5.4
MEDIUMCVE-2024-52942
An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated remote attacker to inject a parameter into an HTTP request, allowing for Cross-Site Scripting (XSS) while viewing archived content. This c... Read more
Affected Products : enterprise_vault- Published: Nov. 18, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2018-10554
An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm parameter, related to components/scheduledreporting; (2) includes/components/xicore/downtime.php, related to... Read more
Affected Products : nagios_xi- Published: Apr. 30, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4627
The ShiftNav WordPress plugin before 1.7.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks whic... Read more
Affected Products : shiftnav- Published: Jan. 23, 2023
- Modified: Apr. 02, 2025
-
5.4
MEDIUMCVE-2024-28191
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert tags in frontend forms if the output is structured in a very specific way. Contao versions 4.13.40 and 5.... Read more
Affected Products : contao- Published: Apr. 09, 2024
- Modified: Jan. 17, 2025
-
5.4
MEDIUMCVE-2024-12825
The Custom Related Posts plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on three AJAX actions in all versions up to, and including, 1.7.3. This makes it possible for authenticated attacke... Read more
Affected Products : custom_related_posts- Published: Feb. 01, 2025
- Modified: Feb. 21, 2025
-
5.4
MEDIUMCVE-2017-1530
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w... Read more
Affected Products : business_process_manager- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2023-2342
Cross-site Scripting (XSS) - Reflected in GitHub repository pimcore/pimcore prior to 10.5.21.... Read more
Affected Products : pimcore- Published: Apr. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-55232
An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts due to missing authorization checks. This flaw enables attackers to delete... Read more
- Published: Dec. 18, 2024
- Modified: Mar. 28, 2025
-
5.4
MEDIUMCVE-2022-4476
The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting ... Read more
- Published: Jan. 16, 2023
- Modified: Apr. 04, 2025
-
5.4
MEDIUMCVE-2024-31425
Cross-Site Request Forgery (CSRF) vulnerability in TMS Amelia.This issue affects Amelia: from n/a through 1.0.95. ... Read more
Affected Products : amelia- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0068
The Product GTIN (EAN, UPC, ISBN) for WooCommerce WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contri... Read more
Affected Products : product_gtin_\(ean\,_upc\,_isbn\)_for_woocommerce- Published: Mar. 06, 2023
- Modified: Mar. 06, 2025
-
5.4
MEDIUMCVE-2022-31298
A cross-site scripting vulnerability in the ads comment section of Haraj v3.7 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.... Read more
Affected Products : haraj- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-33696
SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode user controlled inputs and therefore an authorized attacker can exploit a XSS vulnerability, leading to non-permanently deface or modify... Read more
Affected Products : businessobjects_business_intelligence- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-31303
maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.... Read more
Affected Products : maccms- Published: Jun. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-4795
The Testimonial Slider Shortcode WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Sc... Read more
Affected Products : testimonial_slider_shortcode- Published: Oct. 16, 2023
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2022-3137
The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any authenticated user (such as subscriber) creating a task to perform Stored Cross-Site Scripting by attaching a malicious SVG file... Read more
Affected Products : taskbuilder- Published: Oct. 10, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-7261
There are multiple Persistent XSS vulnerabilities in Radiant CMS 1.1.4. They affect Personal Preferences (Name and Username) and Configuration (Site Title, Dev Site Domain, Page Parts, and Page Fields).... Read more
Affected Products : radiant_cms- Published: Feb. 21, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48200
Cross Site Scripting vulnerability in Grocy v.4.0.3 allows a local attacker to execute arbitrary code and obtain sensitive information via the equipment description component within /equipment/ component.... Read more
- Published: Nov. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-3021
Cross-site Scripting (XSS) - Stored in GitHub repository mkucej/i-librarian-free prior to 5.10.4.... Read more
Affected Products : i\,_librarian- Published: May. 31, 2023
- Modified: Nov. 21, 2024