Latest CVE Feed
-
5.4
MEDIUMCVE-2023-33764
eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component #/de/casting/show/detail/<ID>.... Read more
Affected Products : simpleredak- Published: Jun. 01, 2023
- Modified: Jan. 09, 2025
-
5.4
MEDIUMCVE-2022-44284
Dinstar FXO Analog VoIP Gateway DAG2000-16O is vulnerable to Cross Site Scripting (XSS).... Read more
- Published: Nov. 28, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2022-4458
The amr shortcode any widget WordPress plugin through 4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripti... Read more
Affected Products : amr_shortcode_any_widget- Published: Feb. 13, 2023
- Modified: Mar. 21, 2025
-
5.4
MEDIUMCVE-2022-45038
A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Footer field.... Read more
Affected Products : wbce_cms- Published: Nov. 25, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2022-45215
A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the Add New System User module.... Read more
Affected Products : book_store_management_system- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2023-34977
A cross-site scripting (XSS) vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version... Read more
Affected Products : video_station- Published: Oct. 13, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4551
The Rich Table of Contents WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to ... Read more
Affected Products : rich_table_of_contents- Published: Feb. 13, 2023
- Modified: Mar. 21, 2025
-
5.4
MEDIUMCVE-2016-9130
Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The website name wasn't properly escaped when displayed in the campaign-z... Read more
Affected Products : revive_adserver- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2022-4576
The Easy Bootstrap Shortcode WordPress plugin through 4.5.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scrip... Read more
Affected Products : easy_bootstrap_shortcode- Published: Jan. 23, 2023
- Modified: Apr. 02, 2025
-
5.4
MEDIUMCVE-2022-4650
The HashBar WordPress plugin before 1.3.6 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more
Affected Products : hashbar- Published: Jan. 23, 2023
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2022-4654
The Pricing Tables WordPress Plugin WordPress plugin before 3.2.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more
Affected Products : pricing_tables- Published: Jan. 30, 2023
- Modified: Mar. 28, 2025
-
5.4
MEDIUMCVE-2023-36633
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.... Read more
Affected Products : fortimail- Published: Nov. 14, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0374
The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-... Read more
Affected Products : w4_post_list- Published: Apr. 17, 2023
- Modified: Feb. 06, 2025
-
5.4
MEDIUMCVE-2022-4731
A vulnerability, which was classified as problematic, was found in myapnea up to 29.0.x. Affected is an unknown function of the component Title Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgradin... Read more
Affected Products : myapnea- Published: Dec. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0710
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Cross-Site Scripting by using the 'fname' attribute of the 'mf_thankyou' shortcode to echo unescaped form submissions in versions up to, and including, 3.3.0. This allows authentica... Read more
Affected Products : metform_elementor_contact_form_builder- Published: Jun. 09, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4776
The CC Child Pages WordPress plugin before 1.43 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : cc_child_pages- Published: Jan. 30, 2023
- Modified: Mar. 27, 2025
-
5.4
MEDIUMCVE-2022-4781
The Accordion Shortcodes WordPress plugin through 2.4.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more
Affected Products : accordion_shortcodes- Published: Jan. 30, 2023
- Modified: Mar. 27, 2025
-
5.4
MEDIUMCVE-2022-38814
A stored cross-site scripting (XSS) vulnerability in the auth_settings component of FiberHome AN5506-02-B vRP2521 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the sncfg_loid text field.... Read more
- Published: Sep. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-5000
IBM Financial Transaction Manager 3.2.0 through 3.2.8 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
Affected Products : financial_transaction_manager- Published: Jun. 15, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-1867
The YourChannel plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the save function. This makes it possible for unauthenticated attackers to ch... Read more
Affected Products : yourchannel- Published: Apr. 05, 2023
- Modified: Nov. 21, 2024