Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2022-4473

    The Widget Shortcode WordPress plugin through 0.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting att... Read more

    Affected Products : widget_shortcode
    • Published: Feb. 13, 2023
    • Modified: Mar. 21, 2025
  • 5.4

    MEDIUM
    CVE-2022-4451

    The Social Sharing WordPress plugin before 3.3.45 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attac... Read more

    Affected Products : sassy_social_share
    • Published: Jan. 16, 2023
    • Modified: Apr. 04, 2025
  • 5.4

    MEDIUM
    CVE-2022-4431

    The WOOCS WordPress plugin before 1.3.9.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which... Read more

    • Published: Jan. 16, 2023
    • Modified: Apr. 04, 2025
  • 5.4

    MEDIUM
    CVE-2022-4474

    The Easy Social Feed WordPress plugin before 6.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting atta... Read more

    Affected Products : easy_social_feed
    • Published: Jan. 23, 2023
    • Modified: Apr. 02, 2025
  • 5.4

    MEDIUM
    CVE-2022-4377

    A vulnerability was found in S-CMS 5.0 Build 20220328. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Contact Information Page. The manipulation of the argument Make a Call leads to cross s... Read more

    Affected Products : s-cms
    • Published: Dec. 09, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4480

    The Click to Chat WordPress plugin before 3.18.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack... Read more

    Affected Products : click_to_chat
    • Published: Jan. 16, 2023
    • Modified: Apr. 04, 2025
  • 5.4

    MEDIUM
    CVE-2022-4396

    A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function _get_option of the file pyRdfa/__init__.py. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the pa... Read more

    Affected Products : pyrdfa3
    • Published: Dec. 10, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4472

    The Simple Sitemap WordPress plugin before 3.5.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack... Read more

    Affected Products : simple_sitemap
    • Published: Jan. 30, 2023
    • Modified: Mar. 28, 2025
  • 5.4

    MEDIUM
    CVE-2022-4401

    A vulnerability was found in pallidlight online-course-selection-system. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier o... Read more

    • Published: Dec. 11, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4381

    The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks... Read more

    Affected Products : popup_maker
    • Published: Jan. 02, 2023
    • Modified: Apr. 10, 2025
  • 5.4

    MEDIUM
    CVE-2022-4577

    The Easy Testimonials WordPress plugin before 3.9.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting att... Read more

    Affected Products : easy_testimonials
    • Published: Feb. 06, 2023
    • Modified: Mar. 26, 2025
  • 5.4

    MEDIUM
    CVE-2022-4475

    The Collapse-O-Matic WordPress plugin before 1.8.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting atta... Read more

    Affected Products : collapse-o-matic
    • Published: Jan. 23, 2023
    • Modified: Apr. 02, 2025
  • 5.4

    MEDIUM
    CVE-2022-4484

    The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to p... Read more

    • Published: Jan. 16, 2023
    • Modified: Apr. 08, 2025
  • 5.4

    MEDIUM
    CVE-2022-4460

    The Sidebar Widgets by CodeLights WordPress plugin through 1.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site ... Read more

    Affected Products : codelights-shortcodes-and-widgets
    • Published: Jan. 16, 2023
    • Modified: Apr. 04, 2025
  • 5.4

    MEDIUM
    CVE-2022-4391

    The Vision Interactive For WordPress plugin through 1.5.3 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more

    Affected Products : vision_interactive
    • Published: Jan. 09, 2023
    • Modified: Apr. 09, 2025
  • 5.4

    MEDIUM
    CVE-2022-4231

    A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS 9.3.57595. This issue affects some unknown processing of the component Remember Me Handler. The manipulation leads to session fixiation. The attack may be i... Read more

    Affected Products : zenario
    • Published: Nov. 30, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4235

    RushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious application. This is possible because the application exposes an activity and does not properly validate the data it receives.... Read more

    Affected Products : rushbet
    • Published: Jan. 18, 2023
    • Modified: Apr. 03, 2025
  • 5.4

    MEDIUM
    CVE-2022-4449

    The Page scroll to id WordPress plugin before 1.7.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting att... Read more

    Affected Products : page_scroll_to_id
    • Published: Jan. 16, 2023
    • Modified: Apr. 07, 2025
  • 5.4

    MEDIUM
    CVE-2022-4251

    A vulnerability was found in Movie Ticket Booking System and classified as problematic. Affected by this issue is some unknown functionality of the file editBooking.php. The manipulation leads to cross site scripting. The attack may be launched remotely. ... Read more

    Affected Products : movie_ticket_booking_system
    • Published: Dec. 01, 2022
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2022-4353

    A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this vulnerability is the function IpUtil.getIpAddr. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has b... Read more

    Affected Products : pb-cms
    • Published: Dec. 08, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 293640 Results