Latest CVE Feed
-
5.4
MEDIUMCVE-2018-19350
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.... Read more
Affected Products : seacms- Published: Nov. 17, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1609
A vulnerability was found in Zhong Bang CRMEB Java up to 1.3.4. It has been rated as problematic. This issue affects the function save of the file /api/admin/store/product/save. The manipulation leads to cross site scripting. The attack may be initiated r... Read more
Affected Products : crmeb_java- Published: Mar. 23, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1746
A vulnerability, which was classified as problematic, was found in Dreamer CMS up to 3.5.0. Affected is an unknown function of the component File Upload Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely.... Read more
- Published: Mar. 30, 2023
- Modified: Apr. 04, 2025
-
5.4
MEDIUMCVE-2020-25799
LimeSurvey 3.21.1 is affected by cross-site scripting (XSS) in the Quota component of the Survey page. When the survey quota being viewed, e.g. by an administrative user, the JavaScript code will be executed in the browser.... Read more
Affected Products : limesurvey- Published: Dec. 31, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-14529
Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Investor Module). Supported versions that are affected are 16.1.0.0-16.1.5.1, 18.0.0.0-18.0.2.0 and 19.0.0.0. Easily exploitable vulnerability a... Read more
Affected Products : primavera_portfolio_management- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-38304
An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users and Groups functionality, allowing an attacker to store a malicious payload in the Group Name field when creating a new group.... Read more
Affected Products : webmin- Published: Jul. 31, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0059
The Youzify WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored ... Read more
Affected Products : youzify- Published: Feb. 21, 2023
- Modified: Mar. 12, 2025
-
5.4
MEDIUMCVE-2023-0063
The WordPress Shortcodes WordPress plugin through 1.6.36 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to ... Read more
Affected Products : wordpress_shortcodes- Published: Mar. 06, 2023
- Modified: Mar. 06, 2025
-
5.4
MEDIUMCVE-2023-0097
The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor rol... Read more
- Published: Jan. 30, 2023
- Modified: Apr. 21, 2025
-
5.4
MEDIUMCVE-2023-0282
The YourChannel WordPress plugin before 1.2.2 does not sanitize and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.... Read more
Affected Products : yourchannel- Published: Feb. 06, 2023
- Modified: Mar. 26, 2025
-
5.4
MEDIUMCVE-2023-0372
The EmbedStories WordPress plugin before 0.7.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform St... Read more
Affected Products : embedstories- Published: Feb. 21, 2023
- Modified: Mar. 14, 2025
-
5.4
MEDIUMCVE-2023-0395
The menu shortcode WordPress plugin through 1.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross... Read more
Affected Products : menu_shortcode- Published: Mar. 27, 2023
- Modified: Feb. 19, 2025
-
5.4
MEDIUMCVE-2023-0313
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.... Read more
Affected Products : phpmyfaq- Published: Jan. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0713
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_add_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-... Read more
Affected Products : wicked_folders- Published: Feb. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0718
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber... Read more
Affected Products : wicked_folders- Published: Feb. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-41318
matrix-media-repo is a highly customizable multi-domain media repository for the Matrix chat ecosystem. In affected versions an attacker could upload a malicious piece of media to the media repo, which would then be served with `Content-Disposition: inlin... Read more
Affected Products : matrix-media-repo- Published: Sep. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5909
The watcha (aka com.frograms.watcha) application 2.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : watcha- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2020-15034
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitoring-Setup.php tet parameter.... Read more
Affected Products : nedi- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5930
The Store and Share (aka sg.com.singnet.mystorage.android) application 2.0.18 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifi... Read more
Affected Products : store_and_share- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-23974
Cross-Site Request Forgery (CSRF) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 affecting all registration actions (delete, delete all, edit, update).... Read more
Affected Products : quick_event_manager- Published: Mar. 01, 2023
- Modified: Nov. 21, 2024