Latest CVE Feed
-
5.4
MEDIUMCVE-2024-54419
Cross-Site Request Forgery (CSRF) vulnerability in Mansur Ahamed Ui Slider Filter By Price allows Cross Site Request Forgery.This issue affects Ui Slider Filter By Price: from n/a through 1.1.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024
-
5.4
MEDIUMCVE-2024-25657
An open redirect in the Login/Logout functionality of web management in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS could allow attackers to redirect authenticated users to malicious websites.... Read more
Affected Products :- Published: Mar. 18, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2013-0500
IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.2.0 does not properly handle device files that are created with the NFS protocol but accessed with a non-NFS protocol, which allows remote authenticated users to obtain sensitive information, modify pr... Read more
- Published: Oct. 17, 2013
- Modified: Apr. 11, 2025
-
5.4
MEDIUMCVE-2022-25612
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in Simple Event Planner WordPress plugin <= 1.5.4 allows user with author or higher user rights inject the malicious code via vulnerable parameters: &custom[event_organiser], &cu... Read more
Affected Products : simple_event_planner- Published: Mar. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24455
The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of Announcements (when outputting it in an attribute), which can be created by users as low as Tutor Instructor. This lead to a Stored Cros... Read more
Affected Products : tutor_lms- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-3956
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pod Form widget in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied at... Read more
Affected Products : pods- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-2732
The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'themify_post_slider shortcode in all versions up to, and including, 2.0.8 due to insufficient input sanitization and output escaping on user supplie... Read more
- Published: Mar. 26, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-29918
RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.... Read more
- Published: May. 02, 2023
- Modified: Jan. 30, 2025
-
5.4
MEDIUMCVE-2020-35127
Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS.... Read more
Affected Products : openfire- Published: Dec. 11, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-8444
The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting.... Read more
Affected Products : download_manager- Published: Oct. 30, 2024
- Modified: Apr. 10, 2025
-
5.4
MEDIUMCVE-2020-35275
Coastercms v5.8.18 is affected by cross-site Scripting (XSS). A user can steal a cookie and make the user redirect to any malicious website because it is trigged on the main home page of the product/application.... Read more
Affected Products : coastercms- Published: Dec. 21, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-13068
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).... Read more
Affected Products : grafana- Published: Jun. 30, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-31290
A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Your Name text field.... Read more
Affected Products : known- Published: Jul. 08, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-3790
A vulnerability has been found in Boom CMS 8.0.7 and classified as problematic. Affected by this vulnerability is the function add of the component assets-manager. The manipulation of the argument title/description leads to cross site scripting. The attac... Read more
Affected Products : boom_cms- Published: Jul. 20, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48115
SmarterTools SmarterMail 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.... Read more
Affected Products : smartermail- Published: Dec. 21, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48131
An issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 26, 2024
- Modified: Jun. 17, 2025
-
5.4
MEDIUMCVE-2023-0034
The JetWidgets For Elementor WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above ... Read more
Affected Products : jetwidgets_for_elementor- Published: Feb. 13, 2023
- Modified: Jan. 14, 2025
-
5.4
MEDIUMCVE-2022-27156
Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injection.... Read more
Affected Products : fuel_cms- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24268
The “JetWidgets For Elementor” WordPress Plugin before 1.0.9 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.... Read more
Affected Products : jetwidgets_for_elementor- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0078
The Resume Builder WordPress plugin through 3.1.1 does not sanitize and escape some parameters related to Resume, which could allow users with a role as low as subscriber to perform Stored XSS attacks against higher privilege users... Read more
Affected Products : resume_builder- Published: Mar. 06, 2023
- Modified: May. 05, 2025