Latest CVE Feed
-
5.4
MEDIUMCVE-2022-44071
Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile.... Read more
Affected Products : zenario- Published: Nov. 16, 2022
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2018-6861
Cross Site Scripting (XSS) exists in PHP Scripts Mall Lawyer Search Script 1.0.2 via a profile update parameter.... Read more
Affected Products : lawyer_search_script- Published: Feb. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4545
The Sitemap WordPress plugin before 4.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which c... Read more
Affected Products : sitemap- Published: Jan. 23, 2023
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2023-30338
Multiple stored cross-site scripting (XSS) vulnerabilities in Emlog Pro v2.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Article Title or Article Summary parameters.... Read more
Affected Products : emlog- Published: Apr. 27, 2023
- Modified: Jan. 31, 2025
-
5.4
MEDIUMCVE-2022-4089
A vulnerability was found in rickxy Stock Management System. It has been declared as problematic. This vulnerability affects unknown code of the file /pages/processlogin.php. The manipulation of the argument user leads to cross site scripting. The attack ... Read more
Affected Products : stock_management_system- Published: Nov. 24, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-45970
Alist v3.5.1 is vulnerable to Cross Site Scripting (XSS) via the bulletin board.... Read more
Affected Products : alist- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
5.4
MEDIUMCVE-2022-4115
The Editorial Calendar WordPress plugin before 3.8.3 does not sanitise and escape its settings, allowing users with roles as low as contributor to inject arbitrary web scripts in the plugin admin panel, enabling a Stored Cross-Site Scripting vulnerability... Read more
Affected Products : editorial_calendar- Published: Jun. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4651
The Justified Gallery WordPress plugin before 1.7.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more
Affected Products : justified_gallery- Published: Jan. 30, 2023
- Modified: Mar. 27, 2025
-
5.4
MEDIUMCVE-2022-41676
Raiden MAILD Mail Server website mail field has insufficient filtering for user input. A remote attacker with general user privilege can send email using the website with malicious JavaScript in the input field, which triggers XSS (Reflected Cross-Site Sc... Read more
Affected Products : raidenmaild- Published: Nov. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-24627
A remote stored xss vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.... Read more
- Published: Oct. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-31800
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the forum title parameter.... Read more
Affected Products : chamilo_lms- Published: May. 09, 2023
- Modified: Jan. 29, 2025
-
5.4
MEDIUMCVE-2022-46968
A stored cross-site scripting (XSS) vulnerability in /index.php?page=help of Revenue Collection System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into sent messages.... Read more
Affected Products : revenue_collection_system- Published: Jan. 27, 2023
- Modified: Mar. 28, 2025
-
5.4
MEDIUMCVE-2020-24712
Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.... Read more
Affected Products : gophish- Published: Oct. 28, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4763
The Icon Widget WordPress plugin before 1.3.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks w... Read more
Affected Products : icon_widget- Published: Jan. 30, 2023
- Modified: Mar. 27, 2025
-
5.4
MEDIUMCVE-2022-34317
IBM CICS TX 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM ... Read more
Affected Products : cics_tx- Published: Nov. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-24993
There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when visitors access the article module.... Read more
Affected Products : cmswing- Published: May. 17, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-43169
A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected... Read more
Affected Products : rukovoditel- Published: Oct. 28, 2022
- Modified: May. 08, 2025
-
5.4
MEDIUMCVE-2022-43271
Inhabit Systems Pty Ltd Move CRM version 4, build 260 was discovered to contain a cross-site scripting (XSS) vulnerability via the User profile component.... Read more
Affected Products : move_crm- Published: Dec. 22, 2022
- Modified: Apr. 15, 2025
-
5.4
MEDIUMCVE-2023-3309
A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file ?page=rooms of the component Manage Room Page. The manipulation of the argument Cot... Read more
- Published: Jun. 18, 2023
- Modified: Dec. 18, 2024
-
5.4
MEDIUMCVE-2018-19845
There is Stored XSS in GetSimple CMS 3.3.12 via the admin/edit.php "post-menu" parameter, a related issue to CVE-2018-16325.... Read more
- Published: Dec. 31, 2018
- Modified: Nov. 21, 2024