Latest CVE Feed
-
5.4
MEDIUMCVE-2022-0575
Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.2.0.... Read more
Affected Products : librenms- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0423
The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, and does not have any sanitisation/escaping, allowing any authenticated users, such as subscriber to put Cross-Site Scripting payloads i... Read more
Affected Products : 3d_flipbook- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0397
The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cr... Read more
Affected Products : wpc_smart_wishlist_for_woocommerce- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0398
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks when creating affiliate links, which could allow any authenticated user, such as subscriber to create arbitrary affiliate links, which ... Read more
Affected Products : thirstyaffiliates_affiliate_link_manager- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-0182
Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticated attacker to inject an arbitrary script via an website that uses Quiz And Survey Master.... Read more
- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-4046
The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data.... Read more
Affected Products : gim- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-52888
For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties.... Read more
- Published: Apr. 27, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2024-52885
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Path Traversal
-
5.4
MEDIUMCVE-2024-52855
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a v... Read more
- Published: Dec. 10, 2024
- Modified: Dec. 13, 2024
-
5.4
MEDIUMCVE-2021-46824
Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter to the Update Account form in student_profile.php.... Read more
Affected Products : school_file_management_system- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-46888
An issue was discovered in hledger before 1.23. A Stored Cross-Site Scripting (XSS) vulnerability exists in toBloodhoundJson that allows an attacker to execute JavaScript by encoding user-controlled values in a payload with base64 and parsing them with th... Read more
Affected Products : hledger- Published: May. 21, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-46558
Multiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the username and password fields.... Read more
Affected Products : pbx- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-46372
Scoold 1.47.2 is a Q&A/knowledge base platform written in Java. When writing a Q&A, the markdown editor is vulnerable to a XSS attack when using uppercase letters.... Read more
Affected Products : scoold- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-46253
A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute arbitrary web scripts or HTML.... Read more
Affected Products : anchor_cms- Published: Feb. 01, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-46108
D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance configuration.... Read more
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-46084
uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via "close registration information" input box.... Read more
Affected Products : uscat- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-46026
mysiteforme, as of 19-12-2022, is vulnerable to Cross Site Scripting (XSS) via the add blog tag function in the blog tag in the background blog management.... Read more
- Published: Jan. 20, 2022
- Modified: Apr. 10, 2025
-
5.4
MEDIUMCVE-2021-46087
In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the parameters submitted by the user input form, any user with background permission can affect the system security by entering ... Read more
Affected Products : jfinal_cms- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-46083
uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via the input box of the statistical code.... Read more
Affected Products : uscat- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-45919
Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.... Read more
Affected Products : elfinder- Published: Feb. 08, 2022
- Modified: Nov. 21, 2024