Latest CVE Feed
-
5.4
MEDIUMCVE-2020-9520
A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerability could allows a remote attacker to craft and store malicious content into Vibe such that when the content is viewed by another user ... Read more
Affected Products : vibe- Published: Mar. 25, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-41343
Rogic No-Code Database Builder's file uploading function has insufficient filtering for special characters. A remote attacker with regular user privilege can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack.... Read more
Affected Products : enterprise_cloud_database- Published: Nov. 03, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0891
The StagTools WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Store... Read more
Affected Products : stagtools- Published: May. 02, 2023
- Modified: Jan. 30, 2025
-
5.4
MEDIUMCVE-2023-20096
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. This vulnerability is due to insufficient inpu... Read more
Affected Products : unified_contact_center_express- Published: Apr. 05, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-24081
Multiple stored cross-site scripting (XSS) vulnerabilities in Redrock Software TutorTrac before v4.2.170210 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the reason and location fields of the visits listing ... Read more
Affected Products : tutortrac- Published: Feb. 21, 2023
- Modified: Mar. 14, 2025
-
5.4
MEDIUMCVE-2023-44173
Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Reflected Cross-Site Scripting vulnerability. ... Read more
Affected Products : online_movie_ticket_booking_system- Published: Sep. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-24651
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter on the registration page.... Read more
- Published: Feb. 27, 2023
- Modified: Jun. 27, 2025
-
5.4
MEDIUMCVE-2023-24724
A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient validation and sanitization of data input into the user creation and editing form fields. The product name is ... Read more
Affected Products : web_administration_interface- Published: Apr. 03, 2023
- Modified: Feb. 18, 2025
-
5.4
MEDIUMCVE-2023-25077
Cross-site scripting vulnerability in Authentication Key Settings of EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 to 4.1.2-p1, and EC-CUBE 4.2.0 allows a remote authenticated attacker to inject an arbitrary script.... Read more
Affected Products : ec-cube- Published: Mar. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-45587
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox version 4.4.1 and 4.4.0 and 4.2.0 through 4.2.5 and 4.0.0 through 4.0.3 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 allows attacker to exe... Read more
Affected Products : fortisandbox- Published: Dec. 13, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-43728
Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability due to an unsanitized SSID parameter.... Read more
- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-46471
Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via the text variable scriptContainer of the ScriptViewer.... Read more
Affected Products : yacms- Published: Nov. 20, 2023
- Modified: Jun. 10, 2025
-
5.4
MEDIUMCVE-2023-26448
Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions ... Read more
- Published: Aug. 02, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-22902
Openfind Mail2000 file uploading function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can exploit this vulnerability to inject JavaScript, conducting an XSS attack.... Read more
Affected Products : mail2000- Published: Mar. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-23611
LTI Consumer XBlock implements the consumer side of the LTI specification enabling integration of third-party LTI provider tools. Versions 7.0.0 and above, prior to 7.2.2, are vulnerable to Missing Authorization. Any LTI tool that is integrated with on t... Read more
Affected Products : xblock-lti-consumer- Published: Jan. 26, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-1179
Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.... Read more
Affected Products : openemr- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-35509
An issue was discovered in EyouCMS 1.5.8. There is a Storage XSS vulnerability that can allows an attacker to execute arbitrary Web scripts or HTML by injecting a special payload via the title parameter in the foreground contribution, allowing the attacke... Read more
Affected Products : eyoucms- Published: Aug. 10, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40374
A stored cross-site scripting (XSS) vulnerability was identified in Apperta Foundation OpenEyes 3.5.1. Updating a patient's details allows remote attackers to inject arbitrary web script or HTML via the Address1 parameter. This JavaScript then executes wh... Read more
Affected Products : openeye- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-28367
Cross-site scripting vulnerability in CTA post function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script.... Read more
Affected Products : vk_all_in_one_expansion_unit- Published: May. 23, 2023
- Modified: Jan. 17, 2025
-
5.4
MEDIUMCVE-2019-5947
Cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.10.1 allows remote authenticated attackers to inject arbitrary web script or HTML via the application 'Cabinet'.... Read more
Affected Products : garoon- Published: May. 17, 2019
- Modified: Nov. 21, 2024