Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2020-24993

    There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when visitors access the article module.... Read more

    Affected Products : cmswing
    • Published: May. 17, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-43169

    A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected... Read more

    Affected Products : rukovoditel
    • Published: Oct. 28, 2022
    • Modified: May. 08, 2025
  • 5.4

    MEDIUM
    CVE-2022-43271

    Inhabit Systems Pty Ltd Move CRM version 4, build 260 was discovered to contain a cross-site scripting (XSS) vulnerability via the User profile component.... Read more

    Affected Products : move_crm
    • Published: Dec. 22, 2022
    • Modified: Apr. 15, 2025
  • 5.4

    MEDIUM
    CVE-2023-3309

    A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file ?page=rooms of the component Manage Room Page. The manipulation of the argument Cot... Read more

    • Published: Jun. 18, 2023
    • Modified: Dec. 18, 2024
  • 5.4

    MEDIUM
    CVE-2018-19845

    There is Stored XSS in GetSimple CMS 3.3.12 via the admin/edit.php "post-menu" parameter, a related issue to CVE-2018-16325.... Read more

    Affected Products : getsimple_cms getsimple_cms
    • Published: Dec. 31, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-33764

    eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component #/de/casting/show/detail/<ID>.... Read more

    Affected Products : simpleredak
    • Published: Jun. 01, 2023
    • Modified: Jan. 09, 2025
  • 5.4

    MEDIUM
    CVE-2022-44284

    Dinstar FXO Analog VoIP Gateway DAG2000-16O is vulnerable to Cross Site Scripting (XSS).... Read more

    Affected Products : dag2000-16o_firmware dag2000-16o
    • Published: Nov. 28, 2022
    • Modified: Apr. 25, 2025
  • 5.4

    MEDIUM
    CVE-2022-4458

    The amr shortcode any widget WordPress plugin through 4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripti... Read more

    Affected Products : amr_shortcode_any_widget
    • Published: Feb. 13, 2023
    • Modified: Mar. 21, 2025
  • 5.4

    MEDIUM
    CVE-2022-45038

    A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Footer field.... Read more

    Affected Products : wbce_cms
    • Published: Nov. 25, 2022
    • Modified: Apr. 25, 2025
  • 5.4

    MEDIUM
    CVE-2022-45215

    A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the Add New System User module.... Read more

    Affected Products : book_store_management_system
    • Published: Dec. 02, 2022
    • Modified: Apr. 24, 2025
  • 5.4

    MEDIUM
    CVE-2023-34977

    A cross-site scripting (XSS) vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version... Read more

    Affected Products : video_station
    • Published: Oct. 13, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4551

    The Rich Table of Contents WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to ... Read more

    Affected Products : rich_table_of_contents
    • Published: Feb. 13, 2023
    • Modified: Mar. 21, 2025
  • 5.4

    MEDIUM
    CVE-2016-9130

    Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The website name wasn't properly escaped when displayed in the campaign-z... Read more

    Affected Products : revive_adserver
    • Published: Mar. 28, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2022-4576

    The Easy Bootstrap Shortcode WordPress plugin through 4.5.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scrip... Read more

    Affected Products : easy_bootstrap_shortcode
    • Published: Jan. 23, 2023
    • Modified: Apr. 02, 2025
  • 5.4

    MEDIUM
    CVE-2022-4650

    The HashBar WordPress plugin before 1.3.6 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more

    Affected Products : hashbar
    • Published: Jan. 23, 2023
    • Modified: Apr. 03, 2025
  • 5.4

    MEDIUM
    CVE-2022-4654

    The Pricing Tables WordPress Plugin WordPress plugin before 3.2.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more

    Affected Products : pricing_tables
    • Published: Jan. 30, 2023
    • Modified: Mar. 28, 2025
  • 5.4

    MEDIUM
    CVE-2023-36633

    An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.... Read more

    Affected Products : fortimail
    • Published: Nov. 14, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0374

    The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-... Read more

    Affected Products : w4_post_list
    • Published: Apr. 17, 2023
    • Modified: Feb. 06, 2025
  • 5.4

    MEDIUM
    CVE-2022-4731

    A vulnerability, which was classified as problematic, was found in myapnea up to 29.0.x. Affected is an unknown function of the component Title Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgradin... Read more

    Affected Products : myapnea
    • Published: Dec. 25, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0710

    The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'fname' attribute of the 'mf_thankyou' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authentica... Read more

    • Published: Jun. 09, 2023
    • Modified: Nov. 21, 2024
Showing 20 of 293517 Results