Latest CVE Feed
-
5.4
MEDIUMCVE-2021-36785
The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.... Read more
Affected Products : saml- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-44826
Cross Site Scripting vulnerability in ZenTaoPMS v.18.6 allows a local attacker to obtain sensitive information via a crafted script.... Read more
Affected Products : zentao- Published: Oct. 10, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4855
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se... Read more
Affected Products : rational_doors_next_generation rational_collaborative_lifecycle_management rational_engineering_lifecycle_manager rational_quality_manager rational_rhapsody_design_manager rational_team_concert rhapsody_model_manager collaborative_lifecycle_management engineering_insights engineering_lifecycle_management +6 more products- Published: Jan. 27, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14946
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.... Read more
Affected Products : ultimate_member- Published: Aug. 12, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-50100
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via carousel image editing.... Read more
Affected Products : jfinalcms- Published: Dec. 14, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-5867
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.2.... Read more
Affected Products : phpmyfaq- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-0023
A persistent cross-site scripting (XSS) vulnerability in the Golden VM menu of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on ad... Read more
- Published: Jan. 15, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37453
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).... Read more
Affected Products : axon_pbx- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37458
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).... Read more
Affected Products : axon_pbx- Published: Jul. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-37936
It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search te... Read more
Affected Products : kibana- Published: Nov. 18, 2022
- Modified: Apr. 29, 2025
-
5.4
MEDIUMCVE-2022-29530
An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.... Read more
Affected Products : misp- Published: Apr. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29584
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and JavaScript code is constructed to perform an action.... Read more
Affected Products : mahara- Published: Apr. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-12554
The Peter’s Custom Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.3. This is due to missing nonce validation on the cas_register_post() function. This makes it possible for unauthentica... Read more
Affected Products :- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
5.4
MEDIUMCVE-2023-45879
GibbonEdu Gibbon version 25.0.0 allows HTML Injection via an IFRAME element to the Messager component.... Read more
Affected Products : gibbon- Published: Nov. 14, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-22402
Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users were able to load the first page of apps they were actually not allowed to access. Depending on the selection of apps installed t... Read more
- Published: Jan. 18, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-24566
In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is not properly escaped when shown as condition, which can result in Cross Site Scripting (XSS).... Read more
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-32144
Missing Authorization vulnerability in Welcart Inc. Welcart e-Commerce.This issue affects Welcart e-Commerce: from n/a through 2.9.14.... Read more
Affected Products : welcart_e-commerce- Published: Jun. 11, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-0407
A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack against a user of the web-based manag... Read more
Affected Products : sf300-08_firmware sf302-08_firmware sf302-08p_firmware sf302-08pp_firmware sf302-08mp_firmware sf302-08mpp_firmware sf300-24_firmware sf300-24p_firmware sf300-24pp_firmware sf300-24mp_firmware +46 more products- Published: Aug. 01, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-5809
A stored XSS vulnerability exists in Umbraco CMS <= 8.9.1 or current. An authenticated user can inject arbitrary JavaScript code into iframes when editing content using the TinyMCE rich-text editor, as TinyMCE is configured to allow iframes by default in ... Read more
Affected Products : umbraco_cms- Published: Dec. 30, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-20133
A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because of insufficient validati... Read more
Affected Products : webex_meetings- Published: Jul. 07, 2023
- Modified: Nov. 21, 2024