Latest CVE Feed
-
4.3
MEDIUMCVE-2008-2176
Cross-site scripting (XSS) vulnerability in admin/category.php in Zomplog 3.8.2 allows remote attackers to inject arbitrary web script or HTML via the catname parameter.... Read more
Affected Products : zomplog- Published: May. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2126
Multiple cross-site scripting (XSS) vulnerabilities in Tux CMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to index.php and the (2) returnURL parameter to tux-login.php.... Read more
Affected Products : tux_cms- Published: May. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0193
Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter in a login action.... Read more
Affected Products : h-sphere- Published: Jan. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-2397
Cross-site scripting (XSS) vulnerability in search-results.dot in dotCMS 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of this information is unknown; the details are obtained sole... Read more
Affected Products : dotcms- Published: May. 21, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-4707
Multiple cross-site scripting (XSS) vulnerabilities in PHP GEN before 1.3 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : php_gen- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0364
Cross-site scripting (XSS) vulnerability in MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via a signature containing a JavaScript URI in the SRC attribute of an IMG element, in which the URI uses SGML numeric charac... Read more
Affected Products : mybulletinboard- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0091
Cross-site scripting (XSS) vulnerability in webmail in Open-Xchange 0.8.1-6 and earlier, with "Inline HTML" enabled, allows remote attackers to inject arbitrary web script or HTML via e-mail attachments, which are rendered inline.... Read more
Affected Products : open-xchange- Published: Jan. 05, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-0515
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.87. This is due to missing or incorrect nonce validation on the remove_from_compare function. This makes it... Read more
Affected Products : royal_elementor_addons- Published: Feb. 29, 2024
- Modified: Jan. 08, 2025
-
4.3
MEDIUMCVE-2008-2410
Cross-site scripting (XSS) vulnerability in the servlet engine and Web container in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote authenticated users to inject arbitrary web script or HTML via unspecified... Read more
- Published: May. 22, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-0431
The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 20221130. This is due to missing or incorrect nonce validation on the 'ajax_set_default_card' function. This makes it possib... Read more
Affected Products : gestpay_for_woocommerce- Published: Feb. 28, 2024
- Modified: Feb. 25, 2025
-
4.3
MEDIUMCVE-2008-2167
Cross-site scripting (XSS) vulnerability in ZyXEL ZyWALL 100 allows remote attackers to inject arbitrary web script or HTML via the Referer header, which is not properly handled in a 404 Error page.... Read more
Affected Products : zywall_100- Published: May. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2413
Cross-site scripting (XSS) vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : acgv_news- Published: May. 22, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4179
Multiple cross-site scripting (XSS) vulnerabilities in NooMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) page_id parameter to smileys.php and the (2) q parameter to search.php.... Read more
Affected Products : nooms- Published: Sep. 23, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-2414
Cross-site scripting (XSS) vulnerability in send_email.php in AN Guestbook (ANG) 0.4 allows remote attackers to inject arbitrary web script or HTML via the postid parameter.... Read more
Affected Products : an_guestbook- Published: May. 22, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0222
Cross-site scripting (XSS) vulnerability in fullview.php in AlstraSoft Template Seller Pro allows remote attackers to inject arbitrary web script or HTML via the tempid parameter.... Read more
Affected Products : template_seller- Published: Jan. 16, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-1753
Cross-site scripting (XSS) vulnerability in system/workplace/admin/workplace/sessions.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the searchfilter parameter, a different vector than CVE-2008-1510.... Read more
Affected Products : opencms- Published: Apr. 11, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0443
Cross-site scripting (XSS) vulnerability in archive.php in CheesyBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) realname and (2) comment parameters, or (3) via a javascript URI in the url parameter, when adding a comme... Read more
Affected Products : cheesyblog- Published: Jan. 26, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-35278
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submit... Read more
Affected Products : fortiportal- Published: Jan. 14, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2008-1649
Cross-site scripting (XSS) vulnerability in staticpages/easypublish/index.php in EasyNews 4.0 allows remote attackers to inject arbitrary web script or HTML via the read parameter in an edp_pupublish action.... Read more
Affected Products : easynews- Published: Apr. 02, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-3396
An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project owners to bypass group-level forking restrictions by manipulating API reque... Read more
Affected Products : gitlab- Published: Jul. 10, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication