Latest CVE Feed
-
5.4
MEDIUMCVE-2022-2312
The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing attackers to make logged in user with a role as low as contributor to add/edit and delete students via CSRF attacks. Furthermore, due to... Read more
Affected Products : student_result_or_employee_database- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-2396
A vulnerability classified as problematic was found in SourceCodester Simple e-Learning System 1.0. Affected by this vulnerability is an unknown functionality of the file /vcs/claire_blake. The manipulation of the argument Bio with the input "><script>ale... Read more
Affected Products : simple_e-learning_system- Published: Jul. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-2299
The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads... Read more
Affected Products : allow_svg_files- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-2291
A vulnerability was found in SourceCodester Hotel Management System 2.0. It has been rated as problematic. This issue affects some unknown processing of the file /ci_hms/search of the component Search. The manipulation of the argument search with the inpu... Read more
Affected Products : hotel_management_system- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-2213
A vulnerability was found in SourceCodester Library Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/edit_admin_details.php?id=admin. The manipulation of the argument... Read more
Affected Products : library_management_system- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-2041
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks... Read more
- Published: Jun. 27, 2022
- Modified: Jan. 16, 2025
-
5.4
MEDIUMCVE-2022-2171
The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the set... Read more
Affected Products : progressive_license- Published: Aug. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-25854
This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input or text fields, and an attacker can pass a malicious placeholder value to it to fire the XSS payload.... Read more
Affected Products : tagify- Published: Apr. 29, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-53968
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code in the context of the victim's browser session. By manipulating the DOM environment... Read more
- Published: Mar. 19, 2025
- Modified: Apr. 14, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2022-29880
A vulnerability has been identified in SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM P850 (All versions < V3.00), SICAM ... Read more
Affected Products : 7kg8500-0aa00-0aa0_firmware 7kg8500-0aa00-2aa0_firmware 7kg8500-0aa10-0aa0_firmware 7kg8500-0aa10-2aa0_firmware 7kg8500-0aa30-0aa0_firmware 7kg8500-0aa30-2aa0_firmware 7kg8501-0aa01-0aa0_firmware 7kg8501-0aa01-2aa0_firmware 7kg8501-0aa02-0aa0_firmware 7kg8501-0aa02-2aa0_firmware +62 more products- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29648
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.... Read more
Affected Products : jfinal_cms- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29734
A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.... Read more
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29727
Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.... Read more
Affected Products : enterprise_survey_software- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29602
The gridelements (aka Grid Elements) extension through 7.6.1, 8.x through 8.7.0, 9.x through 9.7.0, and 10.x through 10.2.0 extension for TYPO3 allows XSS.... Read more
Affected Products : grid_elements- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29453
Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Google Maps API key update.... Read more
Affected Products : api_key_for_google_maps- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29426
Authenticated (contributor or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in 2J Slideshow Team's Slideshow, Image Slider by 2J plugin <= 1.3.54 at WordPress.... Read more
Affected Products : 2j_slideshow- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29049
Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not validate the names of promotions defined in Job DSL, allowing attackers with Job/Configure permission to create a promotion with an unsafe name.... Read more
Affected Products : promoted_builds- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29045
Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not escape the name and description of Promoted Build parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable ... Read more
Affected Products : promoted_builds- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29038
Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the name and description of Extended Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by at... Read more
Affected Products : extended_choice_parameter- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-29036
Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a stored ... Read more
Affected Products : credentials- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024