Latest CVE Feed
-
5.4
MEDIUMCVE-2023-43989
An issue in mokumoku chohu mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 24, 2024
- Modified: Jun. 16, 2025
-
5.4
MEDIUMCVE-2018-20632
PHP Scripts Mall Advance B2B Script 2.1.4 has stored Cross-Site Scripting (XSS) via the FIRST NAME or LAST NAME field.... Read more
Affected Products : advance_b2b_script- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-4517
Cross-site Scripting (XSS) - Stored in GitHub repository hestiacp/hestiacp prior to 1.8.6.... Read more
- Published: Oct. 13, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-3493
A vulnerability, which was classified as problematic, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the component Add Employee Handler. The manipulation of the argument First Name/Midd... Read more
Affected Products : human_resource_management_system- Published: Oct. 13, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43830
A Cross-site scripting (XSS) vulnerability in /panel/configuration/financial/ of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into several fields: 'Minimum deposit', 'Maximum deposit' and/or 'Maxi... Read more
Affected Products : subrion- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-45737
Stored cross-site scripting vulnerability exists in the App Settings (/admin/app) page and the Markdown Settings (/admin/markdown) page of GROWI versions prior to v3.5.0. If this vulnerability is exploited, an arbitrary script may be executed on the web b... Read more
Affected Products : growi- Published: Dec. 26, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-46126
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime environments, helping enforce privacy regulations in code. The Fides web application allows users to edit consent and privacy notices suc... Read more
Affected Products : fides- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-22595
IBM B2B Advanced Communications 1.0.0.0 and IBM Multi-Enterprise Integration Gateway 1.0.0.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality ... Read more
- Published: Jul. 31, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48301
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.13, 26.0.8, and 27.1.3 of Nextcloud Server and Nextcloud Enterprise Server, an attacker could insert links into circ... Read more
- Published: Nov. 21, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-35501
Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the duplicate post function.... Read more
Affected Products : blog_pro- Published: Nov. 23, 2022
- Modified: Apr. 28, 2025
-
5.4
MEDIUMCVE-2023-49444
An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image file to the user avatar.... Read more
Affected Products : doracms- Published: Dec. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-25172
Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches, a maliciously crafted URL can be included in a user's full name field to to carry out cross-s... Read more
Affected Products : discourse- Published: Mar. 17, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1200
A vulnerability was found in ehuacui bbs. It has been declared as problematic. This vulnerability affects unknown code. The manipulation of the argument username leads to cross site scripting. The attack can be initiated remotely. The exploit has been dis... Read more
Affected Products : ehuacui-bbs- Published: Mar. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24136
Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead to multiple Cross-Site Scripting vulnerabilities, allowing remote attackers to inject arbitrary JavaScript code or HTML via the below pa... Read more
Affected Products : testimonials_widget- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-5126
The Delete Me plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'plugin_delete_me' shortcode in versions up to, and including, 3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po... Read more
Affected Products : delete_me- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-46640
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in D. Relton Medialist plugin <= 1.3.9 versions.... Read more
Affected Products : medialist- Published: Nov. 08, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-51517
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: from n/a through 1.2.28. ... Read more
Affected Products : calculated_fields_form- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-24260
The “Livemesh Addons for Elementor” WordPress Plugin before 6.8 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.... Read more
Affected Products : addons_for_elementor- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-6738
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagelayer_header_code', 'pagelayer_body_open_code', and 'pagelayer_footer_code' meta fields in all versions up to, and i... Read more
Affected Products : pagelayer- Published: Jan. 04, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-50961
IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sess... Read more
Affected Products : qradar_security_information_and_event_manager- Published: Mar. 27, 2024
- Modified: Mar. 05, 2025