Latest CVE Feed
-
4.3
MEDIUMCVE-2024-33686
Missing Authorization vulnerability in Extend Themes Pathway, Extend Themes Hugo WP, Extend Themes Althea WP, Extend Themes Elevate WP, Extend Themes Brite, Extend Themes Colibri WP, Extend Themes Vertice.This issue affects Pathway: from n/a through 1.0.1... Read more
Affected Products : colibri- Published: Apr. 29, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1032
Cross-site scripting (XSS) vulnerability in the Euroling SiteSeeker module 3.x before 3.4.5 for EPiServer allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the det... Read more
- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-48900
A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipients can only access lists of those they are intended to have access to.... Read more
Affected Products : moodle- Published: Nov. 13, 2024
- Modified: Jun. 13, 2025
-
4.3
MEDIUMCVE-2012-1036
Cross-site scripting (XSS) vulnerability in the telerik HTML editor in DotNetNuke before 5.6.4 and 6.x before 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a message.... Read more
Affected Products : dotnetnuke- Published: Apr. 11, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-29454
Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress allows attackers to upload files. File attachment to messages must be activated.... Read more
Affected Products : better_messages- Published: Jul. 20, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-4742
Cross-site scripting (XSS) vulnerability in user_add.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.... Read more
Affected Products : phplinkexchange- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-33678
Cross-Site Request Forgery (CSRF) vulnerability in ClickCease ClickCease Click Fraud Protection.This issue affects ClickCease Click Fraud Protection: from n/a through 3.2.4. ... Read more
Affected Products :- Published: Apr. 26, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-43827
discourse-footnote is a library providing footnotes for posts in Discourse. ### Impact When posting an inline footnote wrapped in `<a>` tags (e.g. `<a>^[footnote]</a>`, the resulting rendered HTML would include a nested `<a>`, which is stripped by Nokogir... Read more
Affected Products : discourse_footnote- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-1719
The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.3 and in Contact Form 7 – PayPal & Stripe Add-on all versions up to, and including 2.1. This is due to missi... Read more
Affected Products : paypal_\&_stripe_add-on- Published: Feb. 28, 2024
- Modified: Mar. 21, 2025
-
4.3
MEDIUMCVE-2025-24543
Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance allows Cross Site Request Forgery. This issue affects Ultimate Coming Soon & Maintenance: from n/a through 1.0.9.... Read more
Affected Products : ultimate_coming_soon_\&_maintenance- Published: Jan. 24, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-1745
The Testimonial Slider WordPress plugin before 2.3.7 does not properly ensure that a user has the necessary capabilities to edit certain sensitive Testimonial Slider WordPress plugin before 2.3.7 settings, making it possible for users with at least the Au... Read more
- Published: Mar. 26, 2024
- Modified: May. 07, 2025
-
4.3
MEDIUMCVE-2009-3191
Multiple cross-site scripting (XSS) vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to inject arbitrary web script or HTML via the cat parameter to (1) rss.php and (2) opml.php.... Read more
Affected Products : pad_site_scripts- Published: Sep. 15, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-3737
Cross-site scripting (XSS) vulnerability in filemanager/filemanager.php in the control panel in SWsoft Plesk 8.0 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the file parameter.... Read more
Affected Products : plesk_control_panel- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-45660
Nextcloud mail is an email app for the Nextcloud home server platform. In affected versions a missing check of origin, target and cookies allows for an attacker to abuse the proxy endpoint to denial of service a third server. It is recommended that the Ne... Read more
- Published: Oct. 16, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1217
Multiple cross-site scripting (XSS) vulnerabilities in STHS v2 Web Portal 2.2 allow remote attackers to inject arbitrary web script or HTML via the team parameter to (1) prospects.php, (2) prospect.php, or (3) team.php.... Read more
Affected Products : sths_v2_web_portal- Published: Feb. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-26041
Nextcloud Talk is a fully on-premises audio/video and chat communication service. When cron jobs were misconfigured and therefore messages are not expired, the API would still return them while they were then hidden by the frontend code. It is recommended... Read more
- Published: Feb. 27, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-47581
SAP HCM Approve Timesheets Version 4 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.There is low impact on integrity of the application. Confidentiality and availibility are not... Read more
Affected Products :- Published: Dec. 10, 2024
- Modified: Dec. 10, 2024
-
4.3
MEDIUMCVE-2007-2308
Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0 allows remote attackers to inject arbitrary web script or HTML via the rok parameter.... Read more
Affected Products : flowers- Published: Apr. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-1649
The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxDeleteCategory function in all versions up to, and including, 1.0.7.4. This makes it possible for authenticated a... Read more
Affected Products : categorify- Published: Feb. 27, 2024
- Modified: Jan. 07, 2025
-
4.3
MEDIUMCVE-2023-6810
The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to unauthorized access of data due to an improper capability check on the get_settings function in all versions up to, and including, 3.2.4. This makes it possible for authenticated ... Read more
Affected Products :- Published: May. 07, 2024
- Modified: Nov. 21, 2024