Latest CVE Feed
-
4.3
MEDIUMCVE-2011-3859
Cross-site scripting (XSS) vulnerability in the Trending theme before 0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.... Read more
- Published: Sep. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3862
Cross-site scripting (XSS) vulnerability in the Morning Coffee theme before 3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.... Read more
- Published: Sep. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3861
Cross-site scripting (XSS) vulnerability in the Web Minimalist 200901 theme before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.... Read more
- Published: Sep. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4940
Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.10.2, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows remote attac... Read more
- Published: Jul. 29, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5463
The WinCollect agent in IBM Security QRadar SIEM before 7.1.1.569824 allows remote attackers to bypass intended access restrictions by injecting a (1) DLL or (2) configuration file.... Read more
Affected Products : qradar_security_information_and_event_manager- Published: Nov. 29, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3852
Cross-site scripting (XSS) vulnerability in the EvoLve theme before 1.2.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.... Read more
- Published: Sep. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-3648
Cross-site scripting (XSS) vulnerability in KENT-WEB POST-MAIL before 6.7, when Internet Explorer 7 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an unspecified form field.... Read more
- Published: Jun. 28, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-2311
Cross-site scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : web2py- Published: May. 22, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6563
engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to read private entities via unspecified vectors.... Read more
Affected Products : elgg- Published: May. 23, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-1081
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19595 and 19661.... Read more
Affected Products : java_system_identity_manager- Published: Mar. 25, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-6556
Multiple cross-site scripting (XSS) vulnerabilities in the FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrary web script or HTML via the (1) User/FirstName or (2) User/LastName parameter to the edit user page. NOTE:... Read more
Affected Products : firstlastnames- Published: May. 23, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-1035
Cross-site scripting (XSS) vulnerability in the Tasklist module 5.x-1.x before 5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via Cascading Style Sheets (CSS).... Read more
- Published: Mar. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6500
Cross-site scripting (XSS) vulnerability in CodeToad ASP Shopping Cart Script allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.... Read more
Affected Products : asp_shopping_cart_script- Published: Mar. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-6520
The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.0. This is due to missing or incorrect nonce validation on the send_backup_codes_email function... Read more
Affected Products : wp_2fa- Published: Jan. 11, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-23935
Discourse is an open-source messaging platform. In versions 3.0.1 and prior on the `stable` branch and versions 3.1.0.beta2 and prior on the `beta` and `tests-passed` branches, the count of personal messages displayed for a tag is a count of all personal ... Read more
Affected Products : discourse- Published: Mar. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-29192
SilverwareGames.io versions before 1.2.19 allow users with access to the game upload panel to edit download links for games uploaded by other developers. This has been fixed in version 1.2.19.... Read more
Affected Products : silverwaregames- Published: Apr. 10, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-2473
Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this issue has been disputed by the vendor and a third party who is affiliated with the product.... Read more
Affected Products : openwiki- Published: May. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUM- Published: Apr. 11, 2023
- Modified: Feb. 11, 2025
-
4.3
MEDIUMCVE-2023-37984
Missing Authorization vulnerability in ExpressTech Quiz And Survey Master allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through 8.1.10.... Read more
Affected Products : quiz_and_survey_master- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
4.3
MEDIUMCVE-2024-12263
The Child Theme Creator by Orbisius plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cloud_delete() and cloud_update() functions in all versions up to, and including, 1.5.5. This makes it pos... Read more
Affected Products : child_theme_creator- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024