Latest CVE Feed
-
5.4
MEDIUMCVE-2023-25347
A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.... Read more
Affected Products : churchcrm- Published: Apr. 25, 2023
- Modified: Feb. 04, 2025
-
5.4
MEDIUMCVE-2021-20560
IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to h... Read more
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-35174
A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field.... Read more
Affected Products : starterkit- Published: Aug. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-15914
A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker to execute arbitrary Javascript in a target user’s Origin client. An attacker could use this vulnerability to acces... Read more
Affected Products : origin_client- Published: Nov. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-26260
OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacker, due to an improper check of the user agent.... Read more
Affected Products : oxid_eshop- Published: Apr. 11, 2023
- Modified: Feb. 11, 2025
-
5.4
MEDIUMCVE-2014-3826
Cross-site scripting (XSS) vulnerability in MyBB before 1.6.13 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in the edit action of the config-profile_fields module.... Read more
Affected Products : mybb- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-36347
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alpine Press Alpine PhotoTile for Pinterest plugin <= 1.3.1 at WordPress.... Read more
Affected Products : alpine_phototile_for_pinterest- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-26952
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Menu module.... Read more
Affected Products : onekeyadmin- Published: Mar. 08, 2023
- Modified: Mar. 03, 2025
-
5.4
MEDIUMCVE-2022-36533
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.... Read more
- Published: Sep. 16, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-26955
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Admin Group module.... Read more
Affected Products : onekeyadmin- Published: Mar. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2262
Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step.... Read more
Affected Products : android_lint- Published: Sep. 16, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-2316
Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.... Read more
Affected Products : static_analysis_utilities- Published: Nov. 04, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-38704
Cross-Site Request Forgery (CSRF) vulnerability in SEO Redirection plugin <= 8.9 at WordPress, leading to deletion of 404 errors and redirection history.... Read more
Affected Products : seo_redirection- Published: Sep. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-38790
Weave GitOps Enterprise before 0.9.0-rc.5 has a cross-site scripting (XSS) bug allowing a malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permission. The exposure appears in W... Read more
Affected Products : gitops- Published: Sep. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4392
The iPanorama 360 WordPress Virtual Tour Builder plugin through 1.6.29 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability ... Read more
Affected Products : ipanorama_360_wordpress_virtual_tour_builder- Published: Jan. 09, 2023
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2022-44071
Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile.... Read more
Affected Products : zenario- Published: Nov. 16, 2022
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2018-6861
Cross Site Scripting (XSS) exists in PHP Scripts Mall Lawyer Search Script 1.0.2 via a profile update parameter.... Read more
Affected Products : lawyer_search_script- Published: Feb. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4545
The Sitemap WordPress plugin before 4.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which c... Read more
Affected Products : sitemap- Published: Jan. 23, 2023
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2023-30338
Multiple stored cross-site scripting (XSS) vulnerabilities in Emlog Pro v2.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Article Title or Article Summary parameters.... Read more
Affected Products : emlog- Published: Apr. 27, 2023
- Modified: Jan. 31, 2025
-
5.4
MEDIUMCVE-2022-4089
A vulnerability was found in rickxy Stock Management System. It has been declared as problematic. This vulnerability affects unknown code of the file /pages/processlogin.php. The manipulation of the argument user leads to cross site scripting. The attack ... Read more
Affected Products : stock_management_system- Published: Nov. 24, 2022
- Modified: Nov. 21, 2024