Latest CVE Feed
-
5.4
MEDIUMCVE-2022-4480
The Click to Chat WordPress plugin before 3.18.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack... Read more
Affected Products : click_to_chat- Published: Jan. 16, 2023
- Modified: Apr. 04, 2025
-
5.4
MEDIUMCVE-2022-4396
A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function _get_option of the file pyRdfa/__init__.py. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the pa... Read more
Affected Products : pyrdfa3- Published: Dec. 10, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4472
The Simple Sitemap WordPress plugin before 3.5.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack... Read more
Affected Products : simple_sitemap- Published: Jan. 30, 2023
- Modified: Mar. 28, 2025
-
5.4
MEDIUMCVE-2022-4401
A vulnerability was found in pallidlight online-course-selection-system. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier o... Read more
Affected Products : pallidlight_online_course_selection_system- Published: Dec. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4381
The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more
Affected Products : popup_maker- Published: Jan. 02, 2023
- Modified: Apr. 10, 2025
-
5.4
MEDIUMCVE-2022-4577
The Easy Testimonials WordPress plugin before 3.9.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting att... Read more
Affected Products : easy_testimonials- Published: Feb. 06, 2023
- Modified: Mar. 26, 2025
-
5.4
MEDIUMCVE-2022-4475
The Collapse-O-Matic WordPress plugin before 1.8.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting atta... Read more
Affected Products : collapse-o-matic- Published: Jan. 23, 2023
- Modified: Apr. 02, 2025
-
5.4
MEDIUMCVE-2022-4484
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to p... Read more
- Published: Jan. 16, 2023
- Modified: Apr. 08, 2025
-
5.4
MEDIUMCVE-2022-4460
The Sidebar Widgets by CodeLights WordPress plugin through 1.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site ... Read more
Affected Products : codelights-shortcodes-and-widgets- Published: Jan. 16, 2023
- Modified: Apr. 04, 2025
-
5.4
MEDIUMCVE-2022-4391
The Vision Interactive For WordPress plugin through 1.5.3 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : vision_interactive- Published: Jan. 09, 2023
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2022-4231
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue affects some unknown processing of the component Remember Me Handler. The manipulation leads to session fixiation. The attack may be i... Read more
Affected Products : zenario- Published: Nov. 30, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4235
RushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious application. This is possible because the application exposes an activity and does not properly validate the data it receives.... Read more
Affected Products : rushbet- Published: Jan. 18, 2023
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2022-4449
The Page scroll to id WordPress plugin before 1.7.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting att... Read more
Affected Products : page_scroll_to_id- Published: Jan. 16, 2023
- Modified: Apr. 07, 2025
-
5.4
MEDIUMCVE-2022-4251
A vulnerability was found in Movie Ticket Booking System and classified as problematic. Affected by this issue is some unknown functionality of the file editBooking.php. The manipulation leads to cross site scripting. The attack may be launched remotely. ... Read more
Affected Products : movie_ticket_booking_system- Published: Dec. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4353
A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this vulnerability is the function IpUtil.getIpAddr. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has b... Read more
Affected Products : pb-cms- Published: Dec. 08, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-4067
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.... Read more
Affected Products : librenms- Published: Nov. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1540
IBM Doors Web Access 9.5 and 9.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a truste... Read more
- Published: Jan. 26, 2018
- Modified: Feb. 05, 2025
-
5.4
MEDIUMCVE-2017-14921
Stored XSS vulnerability via IMG element at "Filename" of Filemanager in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mishandled during rendering by the application administrator and other users.... Read more
Affected Products : tine_2.0- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2022-48427
In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible... Read more
Affected Products : teamcity- Published: Mar. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-48426
In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible... Read more
Affected Products : teamcity- Published: Mar. 27, 2023
- Modified: Nov. 21, 2024