Latest CVE Feed
-
5.4
MEDIUMCVE-2023-0059
The Youzify WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored ... Read more
Affected Products : youzify- Published: Feb. 21, 2023
- Modified: Mar. 12, 2025
-
5.4
MEDIUMCVE-2023-0063
The WordPress Shortcodes WordPress plugin through 1.6.36 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to ... Read more
Affected Products : wordpress_shortcodes- Published: Mar. 06, 2023
- Modified: Mar. 06, 2025
-
5.4
MEDIUMCVE-2023-0097
The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor rol... Read more
- Published: Jan. 30, 2023
- Modified: Apr. 21, 2025
-
5.4
MEDIUMCVE-2023-0282
The YourChannel WordPress plugin before 1.2.2 does not sanitize and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.... Read more
Affected Products : yourchannel- Published: Feb. 06, 2023
- Modified: Mar. 26, 2025
-
5.4
MEDIUMCVE-2023-0372
The EmbedStories WordPress plugin before 0.7.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform St... Read more
Affected Products : embedstories- Published: Feb. 21, 2023
- Modified: Mar. 14, 2025
-
5.4
MEDIUMCVE-2023-0395
The menu shortcode WordPress plugin through 1.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross... Read more
Affected Products : menu_shortcode- Published: Mar. 27, 2023
- Modified: Feb. 19, 2025
-
5.4
MEDIUMCVE-2023-0313
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.... Read more
Affected Products : phpmyfaq- Published: Jan. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0713
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_add_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-... Read more
Affected Products : wicked_folders- Published: Feb. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0718
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber... Read more
Affected Products : wicked_folders- Published: Feb. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-41318
matrix-media-repo is a highly customizable multi-domain media repository for the Matrix chat ecosystem. In affected versions an attacker could upload a malicious piece of media to the media repo, which would then be served with `Content-Disposition: inlin... Read more
Affected Products : matrix-media-repo- Published: Sep. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5909
The watcha (aka com.frograms.watcha) application 2.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : watcha- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2020-15034
NeDi 1.9C is vulnerable to cross-site scripting (XSS) attack. The application allows an attacker to execute arbitrary JavaScript code via the Monitoring-Setup.php tet parameter.... Read more
Affected Products : nedi- Published: Jul. 07, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-5930
The Store and Share (aka sg.com.singnet.mystorage.android) application 2.0.18 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certifi... Read more
Affected Products : store_and_share- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2023-23974
Cross-Site Request Forgery (CSRF) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 affecting all registration actions (delete, delete all, edit, update).... Read more
Affected Products : quick_event_manager- Published: Mar. 01, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-44765
A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute arbitrary code via a crafted script to Plural Handle of the Data Objects from System & Settings.... Read more
- Published: Oct. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-24957
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code i... Read more
Affected Products : business_automation_workflow- Published: May. 06, 2023
- Modified: Jan. 29, 2025
-
5.4
MEDIUMCVE-2023-25836
There is a Cross-site Scripting vulnerability in Esri Portal for ArcGIS Sites in versions 10.9 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the... Read more
Affected Products : portal_for_arcgis- Published: Jul. 21, 2023
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2023-46483
Cross Site Scripting vulnerability in timetec AWDMS v.2.0 allows an attacker to obtain sensitive information via a crafted payload to the remark parameter of the New Zone function.... Read more
Affected Products : auto_web-based_database_management_system- Published: Nov. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-46783
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bright Plugins Pre-Orders for WooCommerce plugin <= 1.2.13 versions.... Read more
Affected Products : pre-orders_for_woocommerce- Published: Nov. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15944
An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is vulnerable to a persistent XSS attack. An attacker can embed the attack vectors in the dashboard of other users. To exploit this vulner... Read more
Affected Products : gantt-chart- Published: Aug. 04, 2020
- Modified: Nov. 21, 2024