Latest CVE Feed
-
5.4
MEDIUMCVE-2022-35910
In Jellyfin before 10.8, stored XSS allows theft of an admin access token.... Read more
Affected Products : jellyfin- Published: Aug. 19, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-53960
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 13, 2024
-
5.4
MEDIUMCVE-2019-7545
In DbNinja 3.2.7, the Add Host function of the Manage Hosts pages has a Stored Cross-site Scripting (XSS) vulnerability in the User Name field.... Read more
Affected Products : dbninja- Published: Feb. 06, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-35697
Adobe Experience Manager Core Components version 2.20.6 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript conte... Read more
- Published: Aug. 10, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-35297
The application SAP Enable Now does not sufficiently encode user-controlled inputs over the network before it is placed in the output being served to other users, thereby expanding the attack scope, resulting in Stored Cross-Site Scripting (XSS) vulnerabi... Read more
Affected Products : enable_now- Published: Oct. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-35251
A cross-site scripting vulnerability exists in Rocket.chat <v5 due to style injection in the complete chat window, an adversary is able to manipulate not only the style of it, but will also be able to block functionality as well as hijacking the content o... Read more
Affected Products : rocket.chat- Published: Sep. 23, 2022
- Modified: May. 22, 2025
-
5.4
MEDIUMCVE-2022-34786
Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.... Read more
Affected Products : rich_text_publisher- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34650
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.... Read more
Affected Products : team- Published: Jul. 22, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34788
Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.... Read more
Affected Products : matrix_reloaded- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34618
A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the recipe description text field.... Read more
- Published: Aug. 02, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34784
Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Build/Update permission.... Read more
Affected Products : build-metrics- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34619
A stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Shopping Lists item names text field.... Read more
- Published: Aug. 02, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-9003
A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation of this vulnerability would allow an authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other use... Read more
Affected Products : modula_image_gallery- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34191
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.77 and earlier does not escape the name of NetStorm Test parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with I... Read more
Affected Products : ns-nd_integration_performance_publisher- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34193
Jenkins Package Version Plugin 1.0.1 and earlier does not escape the name of Package version parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.... Read more
Affected Products : package_version- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34183
Jenkins Agent Server Parameter Plugin 1.1 and earlier does not escape the name and description of Agent Server parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Con... Read more
Affected Products : agent_server_parameter- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34198
Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier does not escape the name and description of Stash Branch parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/C... Read more
Affected Products : stash_branch_parameter- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34189
Jenkins Image Tag Parameter Plugin 1.10 and earlier does not escape the name and description of Image Tag parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configur... Read more
Affected Products : image_tag_parameter- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34194
Jenkins Readonly Parameter Plugin 1.0.0 and earlier does not escape the name and description of Readonly String and Readonly Text parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by atta... Read more
Affected Products : readonly_parameter- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-34171
In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:ico... Read more
Affected Products : jenkins- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024