Latest CVE Feed
-
5.4
MEDIUMCVE-2023-43704
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "title" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.... Read more
Affected Products : oscommerce- EPSS Score: %0.12
- Published: Sep. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-42029
IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality... Read more
- EPSS Score: %0.06
- Published: Nov. 03, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-8942
Xiuno BBS 4.0.0 has XSS in the adminpage sitename parameter.... Read more
Affected Products : xiuno_bbs- EPSS Score: %0.21
- Published: Mar. 22, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43871
A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).... Read more
Affected Products : wbce_cms- EPSS Score: %0.21
- Published: Sep. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-9120
In Crea8social 2018.2, there is Stored Cross-Site Scripting via a post.... Read more
Affected Products : crea8social- EPSS Score: %0.19
- Published: Mar. 29, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0995
Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to v2.0.1.... Read more
- EPSS Score: %0.09
- Published: Feb. 24, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-2619
The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-le... Read more
Affected Products : elementor_-_header\,_footer_\&_blocks_template elementor_header_\&_footer_builder- Published: May. 16, 2024
- Modified: Jan. 29, 2025
-
5.4
MEDIUMCVE-2018-9155
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the Admin->Logs section (with a logs?logs.type= URI) and the Man... Read more
- EPSS Score: %0.20
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-28522
ZCMS v20170206 was discovered to contain a stored cross-site scripting (XSS) vulnerability via index.php?m=home&c=message&a=add.... Read more
Affected Products : zcms- EPSS Score: %0.20
- Published: Apr. 26, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1117
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.... Read more
Affected Products : pimcore- EPSS Score: %0.00
- Published: Mar. 01, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-43718
Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by authenticated users with database connection update permissions. This issue affects Apache Superset version 1.5.2 and prior versions and v... Read more
Affected Products : superset- EPSS Score: %0.83
- Published: Jan. 16, 2023
- Modified: Apr. 07, 2025
-
5.4
MEDIUMCVE-2022-28599
A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a malicious .pdf file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger a ... Read more
Affected Products : fuel_cms- EPSS Score: %0.25
- Published: May. 03, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36695
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file feature on a manager profile due to lack of input validation.... Read more
Affected Products : deskpro- EPSS Score: %0.21
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4775
A cross-site scripting (XSS) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. This vulnerability allows attackers to inject malicious scripts into web applications for the purpose of running unwanted actions on the end user's... Read more
Affected Products : curam_social_program_management- EPSS Score: %0.11
- Published: Oct. 12, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-3039
IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors.... Read more
Affected Products : rational_requirements_composer- EPSS Score: %0.08
- Published: Sep. 12, 2013
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2022-37430
Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).... Read more
Affected Products : framework- EPSS Score: %0.32
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2023-1067
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.18.... Read more
Affected Products : pimcore- EPSS Score: %0.00
- Published: Feb. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-12745
out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field.... Read more
Affected Products : seeddms- EPSS Score: %0.33
- Published: Jun. 20, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-4514
The Mmm Simple File List WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to per... Read more
Affected Products : mmm_simple_file_list- EPSS Score: %0.12
- Published: Nov. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-12683
Katyshop2 before 2.12 has multiple stored XSS issues.... Read more
Affected Products : katyshop2- EPSS Score: %0.21
- Published: May. 07, 2020
- Modified: Nov. 21, 2024