Latest CVE Feed
-
5.4
MEDIUMCVE-2024-52599
Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 16.1.99.50 and Tuleap Enterprise Edition prior to versions 16.1-4 and 16.0-7, a malicious user with the ability t... Read more
Affected Products : tuleap- Published: Dec. 09, 2024
- Modified: Aug. 22, 2025
-
5.4
MEDIUMCVE-2024-52701
A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page banner parameter.... Read more
Affected Products : piwigo- Published: Nov. 20, 2024
- Modified: May. 22, 2025
-
5.4
MEDIUMCVE-2021-40577
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 in the Add-Users page via the Name parameter.... Read more
Affected Products : online_enrollment_management_system- Published: Nov. 08, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40509
ViewCommon.java in JForum2 2.7.0 allows XSS via a user signature.... Read more
Affected Products : jforum- Published: Sep. 04, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40440
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability... Read more
Affected Products : dynamics_365_business_central- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40377
SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The application fails to sanitize email content, thus allowing one to inject HTML and/or JavaScript into a page that will then be processed and stored by the application.... Read more
Affected Products : smartermail- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40337
Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulnerability can take advantage to exploit multiple web attacks and stole sensitive information. This issue affects: Hitachi Energy LinkOne ... Read more
Affected Products : linkone- Published: Jan. 25, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40292
A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter.... Read more
Affected Products : dzzoffice- Published: Oct. 12, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40094
A DOM-based XSS vulnerability affects SquaredUp for SCOM 5.2.1.6654. If successfully exploited, this vulnerability may allow attackers to inject malicious code into a user's device.... Read more
Affected Products : squaredup- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40214
Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component.... Read more
Affected Products : gibbon- Published: Sep. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40092
A cross-site scripting (XSS) vulnerability in Image Tile in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via an SVG file.... Read more
Affected Products : squaredup- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40093
A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via dashboard actions.... Read more
Affected Products : squaredup- Published: Dec. 07, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2024-20514
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker to conduct a stored cross-site scripting (XSS) attack a... Read more
- Published: Nov. 06, 2024
- Modified: Jul. 31, 2025
-
5.4
MEDIUMCVE-2021-3920
grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : grav-plugin-admin- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-3862
icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : icecoder- Published: Jan. 17, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-3921
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)... Read more
Affected Products : firefly_iii- Published: Nov. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-3841
sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of the user's browser.... Read more
Affected Products : sylius- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024
-
5.4
MEDIUMCVE-2021-3851
firefly-iii is vulnerable to URL Redirection to Untrusted Site... Read more
Affected Products : firefly_iii- Published: Oct. 19, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-3767
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Read more
Affected Products : bookstack- Published: Sep. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-3662
Certain HP Enterprise LaserJet and PageWide MFPs may be vulnerable to stored cross site scripting (XSS).... Read more
- Published: Oct. 29, 2021
- Modified: Nov. 21, 2024