Latest CVE Feed
-
5.4
MEDIUMCVE-2023-0320
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Izmir Katip Celebi University UBYS allows Stored XSS.This issue affects UBYS: before 23.03.16. ... Read more
Affected Products : university_information_management_system- Published: Mar. 20, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0402
The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level perm... Read more
Affected Products : social_warfare- Published: Jan. 19, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0165
The Cost Calculator WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform ... Read more
Affected Products : cost_calculator- Published: Mar. 06, 2023
- Modified: Mar. 06, 2025
-
5.4
MEDIUMCVE-2023-0166
The Product Slider for WooCommerce by PickPlugins WordPress plugin before 1.13.42 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contr... Read more
Affected Products : product_slider_for_woocommerce- Published: Feb. 13, 2023
- Modified: Mar. 21, 2025
-
5.4
MEDIUMCVE-2023-0146
The Naver Map WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stor... Read more
Affected Products : naver_map- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2017-1000023
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document.... Read more
Affected Products : logicaldoc- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2023-0173
The Drag & Drop Sales Funnel Builder for WordPress plugin before 2.6.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role... Read more
Affected Products : drag_\&_drop_sales_funnel_builder- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2023-0154
The GamiPress WordPress plugin before 1.0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Store... Read more
- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2023-0143
The Send PDF for Contact Form 7 WordPress plugin before 0.9.9.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site S... Read more
Affected Products : send_pdf_for_contact_form_7- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2023-0404
The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions related to AJAX actions in versions up to, and including, 2.3.16. This makes it possible for authenticated attackers, wi... Read more
Affected Products : events_made_easy- Published: Jan. 19, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0177
The Social Like Box and Page by WpDevArt WordPress plugin before 0.8.41 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor rol... Read more
Affected Products : social_like_box_and_page- Published: Feb. 13, 2023
- Modified: Mar. 20, 2025
-
5.4
MEDIUMCVE-2023-0066
The Companion Sitemap Generator WordPress plugin through 4.5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and a... Read more
Affected Products : companion_sitemap_generator- Published: Mar. 13, 2023
- Modified: Feb. 27, 2025
-
5.4
MEDIUMCVE-2023-0072
The WC Vendors Marketplace WordPress plugin before 2.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to ... Read more
Affected Products : wc_vendors_marketplace- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2023-0082
The ExactMetrics WordPress plugin before 7.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross... Read more
Affected Products : exactmetrics- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2023-0148
The Gallery Factory Lite WordPress plugin through 2.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to p... Read more
Affected Products : gallery_factory_lite- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2023-0155
An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown... Read more
Affected Products : gitlab- Published: May. 03, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0094
The UpQode Google Maps WordPress plugin through 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to per... Read more
Affected Products : upqode_google_maps- Published: Jan. 16, 2024
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-0144
The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perfor... Read more
Affected Products : event_manager_and_tickets_selling_for_woocommerce- Published: Feb. 06, 2023
- Modified: Mar. 26, 2025
-
5.4
MEDIUMCVE-2023-0149
The WordPrezi WordPress plugin before 0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored ... Read more
Affected Products : wordprezi- Published: Feb. 06, 2023
- Modified: Mar. 25, 2025
-
5.4
MEDIUMCVE-2023-0015
In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intel... Read more
Affected Products : business_objects_business_intelligence_platform- Published: Jan. 10, 2023
- Modified: Nov. 21, 2024