Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2022-45542

    EyouCMS <= 1.6.0 was discovered a reflected-XSS in the FileManager component in GET parameter "filename" when editing any file.... Read more

    Affected Products : eyoucms
    • Published: Jan. 20, 2023
    • Modified: Apr. 03, 2025
  • 5.4

    MEDIUM
    CVE-2022-45758

    SENS v1.0 is vulnerable to Cross Site Scripting (XSS) via com.liuyanzhao.sens.web.controller.admin, getRegister.... Read more

    Affected Products : sens
    • Published: Dec. 12, 2022
    • Modified: Apr. 23, 2025
  • 5.4

    MEDIUM
    CVE-2022-4628

    The Easy PayPal Buy Now Button WordPress plugin before 1.7.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above... Read more

    Affected Products : easy_paypal_buy_now_button
    • Published: Feb. 13, 2023
    • Modified: Mar. 21, 2025
  • 5.4

    MEDIUM
    CVE-2023-0147

    The Flexible Captcha WordPress plugin through 4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform... Read more

    Affected Products : flexible_captcha
    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2022-4666

    The Markup (JSON-LD) structured in schema.org WordPress plugin through 4.8.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributo... Read more

    • Published: Feb. 21, 2023
    • Modified: Mar. 12, 2025
  • 5.4

    MEDIUM
    CVE-2023-0231

    The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Si... Read more

    Affected Products : shoplentor
    • Published: Feb. 21, 2023
    • Modified: Mar. 12, 2025
  • 5.4

    MEDIUM
    CVE-2023-3653

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital Ant E-Commerce Software allows Stored XSS.This issue affects E-Commerce Software: before 11. ... Read more

    Affected Products : digital_ant
    • Published: Aug. 08, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0276

    The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and abov... Read more

    Affected Products : weaver_xtreme_theme_support
    • Published: Apr. 24, 2023
    • Modified: Feb. 04, 2025
  • 5.4

    MEDIUM
    CVE-2023-0167

    The GetResponse for WordPress plugin through 5.5.31 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perfo... Read more

    Affected Products : getresponse
    • Published: Mar. 20, 2023
    • Modified: Feb. 26, 2025
  • 5.4

    MEDIUM
    CVE-2022-46870

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers. This issue affects Apache Zeppelin before 0.8.2. User... Read more

    Affected Products : zeppelin
    • Published: Dec. 16, 2022
    • Modified: Apr. 17, 2025
  • 5.4

    MEDIUM
    CVE-2022-46906

    Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Reflec... Read more

    Affected Products : websoft_hcm
    • Published: Dec. 12, 2022
    • Modified: Apr. 22, 2025
  • 5.4

    MEDIUM
    CVE-2022-47102

    A cross-site scripting (XSS) vulnerability in Student Study Center Management System V 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.... Read more

    • Published: Jan. 12, 2023
    • Modified: Apr. 08, 2025
  • 5.4

    MEDIUM
    CVE-2023-0513

    A vulnerability has been found in isoftforce Dreamer CMS up to 4.0.1 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclos... Read more

    Affected Products : dreamer_cms dreamer_cms
    • Published: Jan. 26, 2023
    • Modified: Apr. 04, 2025
  • 5.4

    MEDIUM
    CVE-2022-40257

    An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field.... Read more

    Affected Products : vince
    • Published: Oct. 10, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4750

    The WP Responsive Testimonials Slider And Widget WordPress plugin through 1.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contribut... Read more

    • Published: Feb. 21, 2023
    • Modified: May. 05, 2025
  • 5.4

    MEDIUM
    CVE-2023-0729

    The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sort_order function. This makes it possible for unauthenti... Read more

    Affected Products : wicked_folders
    • Published: Jun. 09, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4824

    The WP Blog and Widgets WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting a... Read more

    Affected Products : wp_blog_and_widget
    • Published: Feb. 06, 2023
    • Modified: Mar. 26, 2025
  • 5.4

    MEDIUM
    CVE-2023-37625

    A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Link templates.... Read more

    Affected Products : netbox netbox
    • Published: Aug. 10, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-3788

    A vulnerability, which was classified as problematic, has been found in ActiveITzone Active Super Shop CMS 2.5. This issue affects some unknown processing of the component Manage Details Page. The manipulation of the argument name/phone/address leads to c... Read more

    Affected Products : active_super_shop
    • Published: Jul. 20, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-19350

    In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.... Read more

    Affected Products : seacms
    • Published: Nov. 17, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 292803 Results