Latest CVE Feed
-
5.4
MEDIUMCVE-2021-36832
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.... Read more
Affected Products : icegram_engage- Published: Oct. 19, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48620
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48597
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48573
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be e... Read more
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48535
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content... Read more
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36826
Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Manager plugin <= 2.4.13 versions.... Read more
Affected Products : wp_project_manager- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48502
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content... Read more
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-48468
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content... Read more
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36787
The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.... Read more
Affected Products : femanager- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36654
CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme.... Read more
Affected Products : cmsuno- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36568
In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulnerable to Cross Site Scripting Stored... Read more
- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36563
The CheckMK management web console (versions 1.5.0 to 2.0.0) does not sanitise user input in various parameters of the WATO module. This allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScri... Read more
Affected Products : checkmk- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36454
Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\backups.php, 2) blocks\blocks.php, 3) brands\brands.php, 4) comments\comments.php, 5) coupons\coupons.php, 6) feeds\feeds.php, 7) functi... Read more
Affected Products : navigate_cms- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36695
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file feature on a manager profile due to lack of input validation.... Read more
Affected Products : deskpro- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36573
File Upload vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via crafted image upload.... Read more
Affected Products : feehicms- Published: Dec. 15, 2022
- Modified: Apr. 21, 2025
-
5.4
MEDIUMCVE-2021-36550
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Create category m... Read more
Affected Products : tikiwiki_cms\/groupware- Published: Oct. 28, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36352
Stored cross-site scripting (XSS) vulnerability in Care2x Hospital Information Management 2.7 Alpha. The vulnerability has found POST requests in /modules/registration_admission/patient_register.php page with "name_middle", "addr_str", "station", "name_ma... Read more
Affected Products : hospital_information_management- Published: Aug. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-36061
Adobe Connect version 11.2.2 (and earlier) is affected by a secure design principles violation vulnerability via the 'pbMode' parameter. An unauthenticated attacker could leverage this vulnerability to edit or delete recordings on the Connect environment.... Read more
Affected Products : connect- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-33005
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.... Read more
Affected Products : wso2_oauth- Published: May. 16, 2023
- Modified: Jan. 23, 2025
-
5.4
MEDIUMCVE-2023-31153
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface could allow a remote authenticated attacker to inject... Read more
Affected Products : sel-2241_rtac_module_firmware sel-3350_firmware sel-3505_firmware sel-3505-3_firmware sel-3530_firmware sel-3530-4_firmware sel-3532_firmware sel-3555_firmware sel-3560e_firmware sel-3560s_firmware +10 more products- Published: May. 10, 2023
- Modified: Nov. 21, 2024