Latest CVE Feed
-
5.4
MEDIUMCVE-2020-11454
Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowing for the creation of a new dashboard. In order to exploit this vulnerability, a user needs to get access to a shared dashboard or have... Read more
Affected Products : microstrategy_web- Published: Apr. 02, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9311
In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.... Read more
- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-36550
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Table Name field to /dashboard/table-list.php.... Read more
Affected Products : multi_restaurant_table_reservation_system- Published: Jul. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-3185
A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulne... Read more
Affected Products : telepresence_management_suite- Published: Mar. 04, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34963
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the News Feed module.... Read more
Affected Products : open_source_social_network- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0526
The Post Shortcode WordPress plugin through 2.0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform... Read more
Affected Products : post_shortcode- Published: May. 08, 2023
- Modified: Jan. 29, 2025
-
5.4
MEDIUMCVE-2024-1099
A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFileOfData of the file /filex/read-raw. The manipulation of the argument url leads to cross site scripting. It is possible to launch the a... Read more
Affected Products : rebuild- Published: Jan. 31, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0604
The WP Food Manager WordPress plugin before 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : wp_food_manager- Published: Aug. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-29833
The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by using a Cross Site Scripting payload which does not match the regular expression; one example of this is the inclusion of whitespace withi... Read more
Affected Products : photo_gallery- Published: Mar. 26, 2024
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2023-0780
Improper Restriction of Rendered UI Layers or Frames in GitHub repository cockpit-hq/cockpit prior to 2.3.9-dev.... Read more
Affected Products : cockpit- Published: Feb. 11, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2019-14469
In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS.... Read more
Affected Products : nexus_repository_manager- Published: Aug. 22, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43876
A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost field.... Read more
Affected Products : october- Published: Sep. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-43988
An issue in nature fitness saijo mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.... Read more
Affected Products : line- Published: Jan. 24, 2024
- Modified: Jun. 11, 2025
-
5.4
MEDIUMCVE-2018-10806
An issue was discovered in Frog CMS 0.9.5. There is a reflected Cross Site Scripting Vulnerability via the file[current_name] parameter to the admin/?/plugin/file_manager/rename URI. This can be used in conjunction with CSRF.... Read more
- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-4298
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disc... Read more
- Published: May. 19, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-26688
Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the administration interface.... Read more
Affected Products : cs-cart_multivendor- Published: Sep. 25, 2024
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2021-36398
In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.... Read more
Affected Products : moodle- Published: Mar. 06, 2023
- Modified: Mar. 07, 2025
-
5.4
MEDIUMCVE-2022-0256
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : pimcore- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-9465
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export. The CardDAV image export functionality as implemented in Nextcloud/ownCloud allows the download of images stored within a vCard. Due to... Read more
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2024-44851
A stored cross-site scripting (XSS) vulnerability in the Discussion section of Perfex CRM v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Content parameter.... Read more
Affected Products : perfex_crm- Published: Sep. 11, 2024
- Modified: Sep. 13, 2024