Latest CVE Feed
-
5.4
MEDIUMCVE-2022-4716
The WP Popups WordPress plugin before 2.1.4.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks w... Read more
Affected Products : wp_popups- Published: Jan. 23, 2023
- Modified: Apr. 02, 2025
-
5.4
MEDIUMCVE-2023-37657
TwoNav v2.0.28-20230624 is vulnerable to Cross Site Scripting (XSS).... Read more
Affected Products : twonav- Published: Jul. 11, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-3785
A vulnerability was found in PaulPrinting CMS 2018. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument firstname/lastname/address/city/state leads to cross site scripting. The attack ma... Read more
Affected Products : paulprinting- Published: Jul. 20, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2012-1317
The multicast implementation in Cisco IOS before 15.1(1)SY allows remote attackers to cause a denial of service (Route Processor crash) by sending packets at a high rate, aka Bug ID CSCts37717.... Read more
Affected Products : ios- Published: Apr. 23, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2024-41516
A Reflected cross-site scripting (XSS) vulnerability in "ccHandler.aspx" CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "bomid" parameter.... Read more
Affected Products : cadclick- Published: Oct. 04, 2024
- Modified: Jun. 02, 2025
-
5.4
MEDIUMCVE-2024-2017
The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the conditionsRow and switchCountdown functions in all versions up to, and including, 2.7.8. This ma... Read more
Affected Products : countdown_builder- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4752
The Opening Hours WordPress plugin through 2.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform ... Read more
Affected Products : opening_hours- Published: Feb. 21, 2023
- Modified: Mar. 13, 2025
-
5.4
MEDIUMCVE-2023-38307
An issue was discovered in Webmin 2.021. A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Users and Groups functionality. The vulnerability occurs when an authenticated user adds a new user and inserts an XSS payload into the user's... Read more
Affected Products : webmin- Published: Jul. 31, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-6200
The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injection, a variant of Cross-Site-Scripting (XSS) that exploits the templating facilities of the angular framework.... Read more
Affected Products : commerce_cloud- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-38694
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.1.0, a user with access to a specific part of the backoffice is able to inject HTML code into a form where it is not intended. V... Read more
Affected Products : umbraco_cms- Published: Dec. 12, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43725
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_products_status_name_long[1]" parameter, potentially leading to unauthorized execution of scripts with... Read more
Affected Products : oscommerce- Published: Sep. 30, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43874
Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Copyright and Author fields in the Meta & Custom Tags Menu.... Read more
Affected Products : e107_cms- Published: Sep. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43997
An issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
5.4
MEDIUMCVE-2022-4826
The Simple Tooltips WordPress plugin before 2.1.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform... Read more
Affected Products : simple_tooltips- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2024-4731
A vulnerability classified as problematic was found in Campcodes Legal Case Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/role. The manipulation of the argument slug leads to cross site scripting. The... Read more
Affected Products : legal_case_management_system- Published: May. 14, 2024
- Modified: Feb. 19, 2025
-
5.4
MEDIUMCVE-2024-50655
emlog pro <=2.3.18 is vulnerable to Cross Site Scripting (XSS), which allows attackers to write malicious JavaScript code in published articles.... Read more
Affected Products : emlog- Published: Nov. 15, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-50810
hopetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps\comment\views.py, AddCommintView() does not securely filter user input and renders it directly to the frontend page through templates.... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-50838
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/department.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the d and pi parameters.... Read more
Affected Products : e-learning_management_system- Published: Nov. 14, 2024
- Modified: May. 06, 2025
-
5.4
MEDIUMCVE-2023-39777
A cross-site scripting (XSS) vulnerability in the Admin Control Panel of vBulletin 5.7.5 and 6.0.0 allows attackers to execute arbitrary web scripts or HTML via the /login.php?do=login url parameter.... Read more
Affected Products : vbulletin- Published: Sep. 16, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-48119
Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.... Read more
Affected Products : vtiger_crm- Published: Oct. 14, 2024
- Modified: Oct. 30, 2024