Latest CVE Feed
-
5.4
MEDIUMCVE-2019-4663
IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure withi... Read more
Affected Products : websphere_application_server- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1549
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the... Read more
Affected Products : rational_quality_manager- Published: Jul. 10, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-44960
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /general/search.php?searchtype=simple. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into t... Read more
Affected Products : webtareas- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2022-40204
A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via the Host Header in undisclosed pages after login.... Read more
- Published: Dec. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-40317
OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.... Read more
Affected Products : openkm- Published: Sep. 09, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-30452
The MoroSystems EasyMind - Mind Maps plugin before 2.15.0 for Confluence allows persistent XSS when saving a Mind Map with the hyperlink parameter.... Read more
Affected Products : easymind- Published: May. 17, 2023
- Modified: Jan. 23, 2025
-
5.4
MEDIUMCVE-2022-45892
In Planet eStream before 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Search Function, Comments, Batch editing tool, Content Creation, Related Media, Create new user, and Change Username.... Read more
Affected Products : planet_estream- Published: Dec. 25, 2022
- Modified: Apr. 14, 2025
-
5.4
MEDIUMCVE-2021-21358
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 10.4.14, 11.1.1 it has been discovered that the Form Designer backend module of the Form Framework is vulnerable to cross-site scripting. A valid backend user accoun... Read more
Affected Products : typo3- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-30736
Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute javascript interface. To trigger this vulnerability, user interaction is required.... Read more
- Published: Oct. 04, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4624
The GS Logo Slider WordPress plugin before 3.3.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack... Read more
Affected Products : gs_logo_slider- Published: Jan. 23, 2023
- Modified: Apr. 02, 2025
-
5.4
MEDIUMCVE-2023-32061
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, the lack of restrictions on the iFrame tag makes it easy for an attacker to exploit the vulne... Read more
Affected Products : discourse- Published: Jun. 13, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4753
The Print-O-Matic WordPress plugin before 2.1.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : print-o-matic- Published: Jan. 23, 2023
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2022-34297
Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field.... Read more
Affected Products : gii- Published: Dec. 09, 2022
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2020-13889
showAlert() in the administration panel in Bludit 3.12.0 allows XSS.... Read more
Affected Products : bludit- Published: Jun. 06, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4838
The Clean Login WordPress plugin before 1.13.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks ... Read more
Affected Products : clean_login- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2023-32694
Saleor Core is a composable, headless commerce API. Saleor's `validate_hmac_signature` function is vulnerable to timing attacks. Malicious users could abuse this vulnerability on Saleor deployments having the Adyen plugin enabled in order to determine the... Read more
Affected Products : saleor- Published: May. 25, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1984
IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with... Read more
Affected Products : rational_team_concert- Published: Mar. 14, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-33780
A stored cross-site scripting (XSS) vulnerability in TFDi Design smartCARS 3 v0.7.0 and below allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the body of news article.... Read more
Affected Products : smartcars_3- Published: May. 26, 2023
- Modified: Jan. 14, 2025
-
5.4
MEDIUMCVE-2014-3531
Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject arbitrary web script or HTML via the operating system (1) name or (2) description.... Read more
Affected Products : foreman- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2023-3434
Improper Input Validation in the hyperlink interpretation in Savoir-faire Linux's Jami (version 20222284) on Windows. This allows an attacker to send a custom HTML anchor tag to pass a string value to the Windows QRC Handler through the Jami messenger. ... Read more
- Published: Jul. 14, 2023
- Modified: Nov. 21, 2024