Latest CVE Feed
-
5.4
MEDIUMCVE-2023-0333
The TemplatesNext ToolKit WordPress plugin before 3.2.9 does not validate some of its shortcode attributes before using them to generate an HTML tag, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attack... Read more
Affected Products : templatesnext_toolkit- EPSS Score: %0.25
- Published: Feb. 13, 2023
- Modified: Mar. 21, 2025
-
5.4
MEDIUMCVE-2022-46903
Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Stored... Read more
Affected Products : websoft_hcm- EPSS Score: %0.52
- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2022-46904
Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary HTML tags into the page processed by the user's browser, including scripts in the JavaScript programming language, which leads to Self-X... Read more
Affected Products : websoft_hcm- EPSS Score: %0.52
- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2023-0715
The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscribe... Read more
Affected Products : wicked_folders- EPSS Score: %0.06
- Published: Feb. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-37307
In MISP before 2.4.172, title_for_layout is not properly sanitized in Correlations, CorrelationExclusions, and Layouts.... Read more
Affected Products : malware_information_sharing_platform- EPSS Score: %0.10
- Published: Jun. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1359
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sess... Read more
Affected Products : rational_engineering_lifecycle_manager- EPSS Score: %0.27
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2023-0987
A vulnerability classified as problematic was found in SourceCodester Online Pizza Ordering System 1.0. This vulnerability affects unknown code of the file index.php?page=checkout. The manipulation leads to cross site scripting. The attack can be initiate... Read more
- EPSS Score: %0.07
- Published: Feb. 23, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-43720
An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the toast message displayed when a user deletes that specific CSS template record. This issue affects Apache Su... Read more
Affected Products : superset- EPSS Score: %0.33
- Published: Jan. 16, 2023
- Modified: Apr. 07, 2025
-
5.4
MEDIUMCVE-2022-3452
A vulnerability was found in SourceCodester Book Store Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /category.php. The manipulation of the argument category_name leads to cross site script... Read more
Affected Products : book_store_management_system- EPSS Score: %0.08
- Published: Oct. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1179
A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. Affected is an unknown function of the component Add Supplier Handler. The manipulation of the argument company_name/province/... Read more
Affected Products : computer_parts_sales_and_inventory_system- EPSS Score: %0.07
- Published: Mar. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1181
Cross-site Scripting (XSS) - Stored in GitHub repository icret/easyimages2.0 prior to 2.6.7.... Read more
Affected Products : easyimages2.0- EPSS Score: %0.06
- Published: Mar. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-37886
Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2. ... Read more
Affected Products :- Published: Mar. 25, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1702
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.... Read more
Affected Products : pimcore- EPSS Score: %0.00
- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4788
The Embed PDF WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stor... Read more
Affected Products : embed_pdf- EPSS Score: %0.12
- Published: Feb. 27, 2023
- Modified: Mar. 11, 2025
-
5.4
MEDIUMCVE-2022-34648
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress.... Read more
Affected Products : uploading_svg\,_webp_and_ico_files- EPSS Score: %0.19
- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0060
The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to... Read more
- EPSS Score: %0.25
- Published: Feb. 13, 2023
- Modified: Mar. 21, 2025
-
5.4
MEDIUMCVE-2023-0074
The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perfor... Read more
Affected Products : wp_social_widget- EPSS Score: %0.14
- Published: Jan. 30, 2023
- Modified: Mar. 27, 2025
-
5.4
MEDIUMCVE-2023-0073
The Client Logo Carousel WordPress plugin through 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to p... Read more
Affected Products : client_logo_carousel- EPSS Score: %0.12
- Published: Mar. 13, 2023
- Modified: Feb. 27, 2025
-
5.4
MEDIUMCVE-2023-40684
IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially le... Read more
Affected Products : content_navigator- EPSS Score: %0.07
- Published: Oct. 04, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9520
A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerability could allows a remote attacker to craft and store malicious content into Vibe such that when the content is viewed by another user ... Read more
Affected Products : vibe- EPSS Score: %0.21
- Published: Mar. 25, 2020
- Modified: Nov. 21, 2024