Latest CVE Feed
-
5.4
MEDIUMCVE-2022-4837
The CPO Companion WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : cpo_companion- Published: Jan. 30, 2023
- Modified: Apr. 21, 2025
-
5.4
MEDIUMCVE-2021-42233
The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any user opens a particular blog hosted on an attackers' site, XSS may occur.... Read more
- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-33795
A stored cross-site scripting (XSS) vulnerability in the Create Contact Roles (/tenancy/contact-roles/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.... Read more
- Published: May. 24, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-44955
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the Chat function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Messages field.... Read more
Affected Products : webtareas- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2022-44961
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /forums/editforum.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.... Read more
Affected Products : webtareas- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2022-4508
The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : convertkit_-_email_marketing\,_email_newsletter_and_landing_pages- Published: Jan. 16, 2023
- Modified: Apr. 04, 2025
-
5.4
MEDIUMCVE-2022-45542
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the FileManager component in GET parameter "filename" when editing any file.... Read more
Affected Products : eyoucms- Published: Jan. 20, 2023
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2022-45758
SENS v1.0 is vulnerable to Cross Site Scripting (XSS) via com.liuyanzhao.sens.web.controller.admin, getRegister.... Read more
Affected Products : sens- Published: Dec. 12, 2022
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2022-4628
The Easy PayPal Buy Now Button WordPress plugin before 1.7.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above... Read more
Affected Products : easy_paypal_buy_now_button- Published: Feb. 13, 2023
- Modified: Mar. 21, 2025
-
5.4
MEDIUMCVE-2023-0147
The Flexible Captcha WordPress plugin through 4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform... Read more
Affected Products : flexible_captcha- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2022-4666
The Markup (JSON-LD) structured in schema.org WordPress plugin through 4.8.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributo... Read more
Affected Products : markup_\(json-ld\)_structured_in_schema.org- Published: Feb. 21, 2023
- Modified: Mar. 12, 2025
-
5.4
MEDIUMCVE-2023-0231
The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Si... Read more
Affected Products : shoplentor- Published: Feb. 21, 2023
- Modified: Mar. 12, 2025
-
5.4
MEDIUMCVE-2023-3653
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital Ant E-Commerce Software allows Stored XSS.This issue affects E-Commerce Software: before 11. ... Read more
Affected Products : digital_ant- Published: Aug. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0276
The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and abov... Read more
Affected Products : weaver_xtreme_theme_support- Published: Apr. 24, 2023
- Modified: Feb. 04, 2025
-
5.4
MEDIUMCVE-2023-0167
The GetResponse for WordPress plugin through 5.5.31 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perfo... Read more
Affected Products : getresponse- Published: Mar. 20, 2023
- Modified: Feb. 26, 2025
-
5.4
MEDIUMCVE-2022-46870
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin allows logged-in users to execute arbitrary javascript in other users' browsers. This issue affects Apache Zeppelin before 0.8.2. User... Read more
Affected Products : zeppelin- Published: Dec. 16, 2022
- Modified: Apr. 17, 2025
-
5.4
MEDIUMCVE-2022-46906
Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Reflec... Read more
Affected Products : websoft_hcm- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2022-47102
A cross-site scripting (XSS) vulnerability in Student Study Center Management System V 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.... Read more
- Published: Jan. 12, 2023
- Modified: Apr. 08, 2025
-
5.4
MEDIUMCVE-2023-0513
A vulnerability has been found in isoftforce Dreamer CMS up to 4.0.1 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclos... Read more
- Published: Jan. 26, 2023
- Modified: Apr. 04, 2025
-
5.4
MEDIUMCVE-2022-40257
An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field.... Read more
Affected Products : vince- Published: Oct. 10, 2022
- Modified: Nov. 21, 2024