Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2022-4650

    The HashBar WordPress plugin before 1.3.6 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more

    Affected Products : hashbar
    • Published: Jan. 23, 2023
    • Modified: Apr. 03, 2025
  • 5.4

    MEDIUM
    CVE-2022-4654

    The Pricing Tables WordPress Plugin WordPress plugin before 3.2.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more

    Affected Products : pricing_tables
    • Published: Jan. 30, 2023
    • Modified: Mar. 28, 2025
  • 5.4

    MEDIUM
    CVE-2023-36633

    An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.... Read more

    Affected Products : fortimail
    • Published: Nov. 14, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0374

    The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-... Read more

    Affected Products : w4_post_list
    • Published: Apr. 17, 2023
    • Modified: Feb. 06, 2025
  • 5.4

    MEDIUM
    CVE-2022-4731

    A vulnerability, which was classified as problematic, was found in myapnea up to 29.0.x. Affected is an unknown function of the component Title Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgradin... Read more

    Affected Products : myapnea
    • Published: Dec. 25, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0710

    The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'fname' attribute of the 'mf_thankyou' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authentica... Read more

    • Published: Jun. 09, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4776

    The CC Child Pages WordPress plugin before 1.43 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more

    Affected Products : cc_child_pages
    • Published: Jan. 30, 2023
    • Modified: Mar. 27, 2025
  • 5.4

    MEDIUM
    CVE-2022-4781

    The Accordion Shortcodes WordPress plugin through 2.4.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more

    Affected Products : accordion_shortcodes
    • Published: Jan. 30, 2023
    • Modified: Mar. 27, 2025
  • 5.4

    MEDIUM
    CVE-2022-38814

    A stored cross-site scripting (XSS) vulnerability in the auth_settings component of FiberHome AN5506-02-B vRP2521 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the sncfg_loid text field.... Read more

    Affected Products : an5506-02-b_firmware an5506-02-b
    • Published: Sep. 15, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2020-5000

    IBM Financial Transaction Manager 3.2.0 through 3.2.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more

    Affected Products : financial_transaction_manager
    • Published: Jun. 15, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-1867

    The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the save function. This makes it possible for unauthenticated attackers to ch... Read more

    Affected Products : yourchannel
    • Published: Apr. 05, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-20204

    A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability ex... Read more

    • Published: Aug. 03, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-39518

    social-media-skeleton is an uncompleted social media project implemented using PHP, MySQL, CSS, JavaScript, and HTML. Versions 1.0.0 until 1.0.3 have a stored cross-site scripting vulnerability. The problem is patched in v1.0.3. ... Read more

    Affected Products : social-media-skeleton
    • Published: Aug. 08, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0062

    The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to per... Read more

    Affected Products : ean_for_woocommerce
    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2023-0175

    The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contribut... Read more

    Affected Products : smart_logo_showcase_lite
    • Published: Mar. 20, 2023
    • Modified: Feb. 26, 2025
  • 5.4

    MEDIUM
    CVE-2023-0230

    The VK All in One Expansion Unit WordPress plugin before 9.86.0.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to pe... Read more

    Affected Products : vk_all_in_one_expansion_unit
    • Published: Feb. 27, 2023
    • Modified: Mar. 10, 2025
  • 5.4

    MEDIUM
    CVE-2023-0301

    Cross-site Scripting (XSS) - Stored in GitHub repository alfio-event/alf.io prior to Alf.io 2.0-M4-2301.... Read more

    Affected Products : alf.io alf
    • Published: Jan. 14, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0536

    The Wp-D3 WordPress plugin through 2.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored C... Read more

    Affected Products : wp-d3
    • Published: May. 08, 2023
    • Modified: May. 05, 2025
  • 5.4

    MEDIUM
    CVE-2023-1126

    The WP FEvents Book WordPress plugin through 0.46 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Cross-Site Scripting attacks... Read more

    Affected Products : wp_fevents_book
    • Published: Apr. 24, 2023
    • Modified: Feb. 04, 2025
  • 5.4

    MEDIUM
    CVE-2023-42431

    Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine user context.... Read more

    Affected Products : bluespice
    • Published: Oct. 30, 2023
    • Modified: Nov. 21, 2024
Showing 20 of 293527 Results