Latest CVE Feed
-
5.4
MEDIUM- EPSS Score: %0.50
- Published: Dec. 31, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8777
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT element in an SVG document.... Read more
Affected Products : alfresco- EPSS Score: %0.73
- Published: Mar. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-14959
Multiple XSS vulnerabilities in the Easy Testimonials plugin before 3.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the wp-admin/post.php Client Name, Position, Web Address, Other, Location Reviewed, Product Reviewed, I... Read more
Affected Products : easy_testimonials- EPSS Score: %0.16
- Published: Jun. 22, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9008
Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile editor.... Read more
Affected Products : blackboard_learn- EPSS Score: %0.18
- Published: Feb. 25, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-2410
SAP Business One, 9.2, 9.3, browser access does not sufficiently encode user controlled inputs, which results in a Cross-Site Scripting (XSS) vulnerability.... Read more
Affected Products : business_one- EPSS Score: %0.28
- Published: Apr. 10, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15006
Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php.... Read more
Affected Products : bludit- EPSS Score: %0.19
- Published: Jun. 24, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-42584
A Stored Cross Site Scripting (XSS) issue exists in Convos-Chat before 6.32.... Read more
Affected Products : convos- EPSS Score: %0.26
- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-14877
An issue was discovered in WeaselCMS v0.3.5. XSS exists via Site Language, Site Title, Site Description, and Site Keywords on the SETTINGS page.... Read more
Affected Products : weaselcms- EPSS Score: %0.19
- Published: Aug. 03, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-14890
Vectra Networks Cognito Brain and Sensor before 4.2 contains a cross-site scripting (XSS) vulnerability in the Web Management Console.... Read more
Affected Products : cognito- EPSS Score: %0.29
- Published: Sep. 21, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-14964
An issue was discovered in EMLsoft 5.4.5. XSS exists via the eml/upload/eml/?action=address&do=edit page.... Read more
Affected Products : emlsoft- EPSS Score: %0.21
- Published: Aug. 06, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24271
The “Ultimate Addons for Elementor” WordPress Plugin before 1.30.0 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.... Read more
Affected Products : ultimate_addons_for_elementor- EPSS Score: %0.22
- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24468
The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low as Contributors to exploit stored XSS issues... Read more
Affected Products : leaflet_map- EPSS Score: %0.18
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24571
The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues... Read more
Affected Products : hd_quiz- EPSS Score: %0.18
- Published: Aug. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-19306
The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.... Read more
Affected Products : lead_magnet- EPSS Score: %0.40
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24969
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_templa... Read more
- EPSS Score: %0.21
- Published: Dec. 27, 2021
- Modified: Mar. 21, 2025
-
5.4
MEDIUMCVE-2021-20484
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosur... Read more
Affected Products : sterling_file_gateway- EPSS Score: %0.22
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20506
IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted s... Read more
- EPSS Score: %0.21
- Published: Mar. 30, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-45866
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Student Attendance Management System 1.0 via the couse filed in index.php.... Read more
Affected Products : student_attendance_management_system- EPSS Score: %0.20
- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25790
Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone N... Read more
Affected Products : house_rental_and_property_listing_php- EPSS Score: %0.16
- Published: Jul. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20855
Cross-site scripting vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.... Read more
- EPSS Score: %0.21
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024