Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2023-0015

    In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intel... Read more

    • Published: Jan. 10, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0111

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.... Read more

    Affected Products : memos
    • Published: Jan. 07, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0081

    The MonsterInsights WordPress plugin before 8.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cr... Read more

    Affected Products : monsterinsights
    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2023-0065

    The i2 Pros & Cons WordPress plugin through 1.3.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform... Read more

    Affected Products : i2_pros_\&_cons
    • Published: Mar. 06, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2023-0150

    The Cloak Front End Email WordPress plugin before 1.9.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to p... Read more

    Affected Products : cloak_front_end_email
    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2022-4946

    The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will redirect users to a... Read more

    Affected Products : frontend_post_wordpress_plugin
    • Published: Jun. 05, 2023
    • Modified: Jan. 08, 2025
  • 5.4

    MEDIUM
    CVE-2022-4762

    The Materialis Companion WordPress plugin before 1.3.40 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting... Read more

    Affected Products : materialis_companion
    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2022-4760

    The OneClick Chat to Order WordPress plugin before 1.0.4.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Script... Read more

    Affected Products : oneclick_chat_to_order
    • Published: Jan. 23, 2023
    • Modified: Apr. 02, 2025
  • 5.4

    MEDIUM
    CVE-2022-4834

    The CPT Bootstrap Carousel WordPress plugin through 1.12 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scriptin... Read more

    Affected Products : cpt_bootstrap_carousel
    • Published: Jan. 30, 2023
    • Modified: Mar. 27, 2025
  • 5.4

    MEDIUM
    CVE-2022-4756

    The My YouTube Channel WordPress plugin before 3.23.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting a... Read more

    Affected Products : my_youtube_channel
    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2022-4775

    The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more

    Affected Products : geodirectory geodirectory
    • Published: Jan. 23, 2023
    • Modified: Apr. 03, 2025
  • 5.4

    MEDIUM
    CVE-2022-4833

    The YourChannel: Everything you want in a YouTube plugin WordPress plugin before 1.2.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perf... Read more

    Affected Products : yourchannel
    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2022-4787

    Themify Shortcodes WordPress plugin before 2.0.8 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more

    Affected Products : shortcodes
    • Published: Jan. 30, 2023
    • Modified: Mar. 27, 2025
  • 5.4

    MEDIUM
    CVE-2022-4790

    The WP Google My Business Auto Publish WordPress plugin before 3.4 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more

    • Published: Jan. 23, 2023
    • Modified: Apr. 02, 2025
  • 5.4

    MEDIUM
    CVE-2022-4754

    The Easy Social Box / Page Plugin WordPress plugin through 4.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and a... Read more

    Affected Products : easy_social_box
    • Published: Feb. 21, 2023
    • Modified: Mar. 12, 2025
  • 5.4

    MEDIUM
    CVE-2022-4717

    The Strong Testimonials WordPress plugin before 3.0.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting a... Read more

    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
  • 5.4

    MEDIUM
    CVE-2022-4782

    The ClickFunnels WordPress plugin through 3.1.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.... Read more

    Affected Products : clickfunnels
    • Published: Aug. 16, 2023
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4757

    The List Pages Shortcode WordPress plugin before 1.7.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting ... Read more

    Affected Products : list_pages_shortcode
    • Published: Feb. 27, 2023
    • Modified: Mar. 10, 2025
  • 5.4

    MEDIUM
    CVE-2022-4751

    The Word Balloon WordPress plugin before 4.19.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more

    Affected Products : word_balloon
    • Published: Jan. 23, 2023
    • Modified: Apr. 03, 2025
  • 5.4

    MEDIUM
    CVE-2022-4825

    The WP-ShowHide WordPress plugin before 1.05 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks wh... Read more

    Affected Products : download_wp-showhide
    • Published: Feb. 06, 2023
    • Modified: Mar. 25, 2025
Showing 20 of 293639 Results