Latest CVE Feed
-
5.4
MEDIUMCVE-2022-3452
A vulnerability was found in SourceCodester Book Store Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /category.php. The manipulation of the argument category_name leads to cross site script... Read more
Affected Products : book_store_management_system- Published: Oct. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1179
A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. Affected is an unknown function of the component Add Supplier Handler. The manipulation of the argument company_name/province/... Read more
Affected Products : computer_parts_sales_and_inventory_system- Published: Mar. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1181
Cross-site Scripting (XSS) - Stored in GitHub repository icret/easyimages2.0 prior to 2.6.7.... Read more
Affected Products : easyimages2.0- Published: Mar. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-37886
Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2. ... Read more
Affected Products :- Published: Mar. 25, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1702
Cross-site Scripting (XSS) - Generic in GitHub repository pimcore/pimcore prior to 10.5.20.... Read more
Affected Products : pimcore- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4788
The Embed PDF WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stor... Read more
Affected Products : embed_pdf- Published: Feb. 27, 2023
- Modified: Mar. 11, 2025
-
5.4
MEDIUMCVE-2022-34648
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress.... Read more
Affected Products : uploading_svg\,_webp_and_ico_files- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0060
The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to... Read more
- Published: Feb. 13, 2023
- Modified: Mar. 21, 2025
-
5.4
MEDIUMCVE-2023-0074
The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perfor... Read more
Affected Products : wp_social_widget- Published: Jan. 30, 2023
- Modified: Mar. 27, 2025
-
5.4
MEDIUMCVE-2023-0073
The Client Logo Carousel WordPress plugin through 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to p... Read more
Affected Products : client_logo_carousel- Published: Mar. 13, 2023
- Modified: Feb. 27, 2025
-
5.4
MEDIUMCVE-2023-40684
IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially le... Read more
Affected Products : content_navigator- Published: Oct. 04, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9520
A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerability could allows a remote attacker to craft and store malicious content into Vibe such that when the content is viewed by another user ... Read more
Affected Products : vibe- Published: Mar. 25, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-41343
Rogic No-Code Database Builder's file uploading function has insufficient filtering for special characters. A remote attacker with regular user privilege can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack.... Read more
Affected Products : enterprise_cloud_database- Published: Nov. 03, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0891
The StagTools WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Store... Read more
Affected Products : stagtools- Published: May. 02, 2023
- Modified: Jan. 30, 2025
-
5.4
MEDIUMCVE-2023-20096
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. This vulnerability is due to insufficient inpu... Read more
Affected Products : unified_contact_center_express- Published: Apr. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-24081
Multiple stored cross-site scripting (XSS) vulnerabilities in Redrock Software TutorTrac before v4.2.170210 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the reason and location fields of the visits listing ... Read more
Affected Products : tutortrac- Published: Feb. 21, 2023
- Modified: Mar. 14, 2025
-
5.4
MEDIUMCVE-2023-44173
Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Reflected Cross-Site Scripting vulnerability. ... Read more
Affected Products : online_movie_ticket_booking_system- Published: Sep. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-24651
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter on the registration page.... Read more
- Published: Feb. 27, 2023
- Modified: Jun. 27, 2025
-
5.4
MEDIUMCVE-2023-24724
A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient validation and sanitization of data input into the user creation and editing form fields. The product name is ... Read more
Affected Products : web_administration_interface- Published: Apr. 03, 2023
- Modified: Feb. 18, 2025
-
5.4
MEDIUMCVE-2023-25077
Cross-site scripting vulnerability in Authentication Key Settings of EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 to 4.1.2-p1, and EC-CUBE 4.2.0 allows a remote authenticated attacker to inject an arbitrary script.... Read more
Affected Products : ec-cube- Published: Mar. 06, 2023
- Modified: Nov. 21, 2024