Latest CVE Feed
-
4.3
MEDIUMCVE-2009-2350
Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header o... Read more
Affected Products : internet_explorer- Published: Jul. 07, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-1036
Cross-site scripting (XSS) vulnerability in the telerik HTML editor in DotNetNuke before 5.6.4 and 6.x before 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a message.... Read more
Affected Products : dotnetnuke- Published: Apr. 11, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-40598
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed information for log events. (The log_deleted attribute is not applied to entries.)... Read more
Affected Products : mediawiki- Published: Jul. 07, 2024
- Modified: Mar. 25, 2025
-
4.3
MEDIUMCVE-2020-8117
Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non-public event.... Read more
Affected Products : nextcloud_server- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-3844
Cross-site scripting (XSS) vulnerability in vBulletin 4.1.12 allows remote attackers to inject arbitrary web script or HTML via a long string in the subject parameter when creating a post.... Read more
Affected Products : vbulletin- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-47858
Mattermost fails to properly verify the permissions needed for viewing archived public channels, allowing a member of one team to get details about the archived public channels of another team via the GET /api/v4/teams/<team-id>/channels/deleted endpoint... Read more
- Published: Jan. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-4854
Cross-site scripting (XSS) vulnerability in the WP Construction Mode plugin 1.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wuc_logo parameter in a save action to wp-admin/admin.php.... Read more
Affected Products : wp_contruction_mode- Published: Jul. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-2572
Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote attackers to inject arbitrary web script or HTML via the Subject of an email.... Read more
Affected Products : threewp_email_reflector- Published: Jun. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-4881
Multiple cross-site scripting (XSS) vulnerabilities in David Bennett PHP-Post (PHPp) 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the replyuser parameter in (a) pm.php; (2) the txt_jumpto parameter in (b) dropdown.... Read more
Affected Products : php-post- Published: Sep. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-3784
Cross-site scripting (XSS) vulnerability in the Belkin G Plus Router F5D7231-4 with firmware 4.05.03 allows remote attackers to inject arbitrary web script or HTML via a hostname of a DHCP client.... Read more
Affected Products : f5d7231-4- Published: Jul. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-4394
Cross-site scripting (XSS) vulnerability in apps/files/js/filelist.js in ownCloud before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter.... Read more
- Published: Sep. 05, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-1026
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the listPostsCategory function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscrib... Read more
Affected Products : wp_meta_seo- Published: Feb. 28, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-5160
Mattermost fails to check the Show Full Name option at the /api/v4/teams/TEAM_ID/top/team_members endpoint allowing a member to get the full name of another user even if the Show Full Name option was disabled ... Read more
- Published: Oct. 02, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-7142
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified oAuth API functions.... Read more
Affected Products : open-xchange_appsuite- Published: Jan. 26, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-7277
Multiple cross-site scripting (XSS) vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.8 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP Referer header to saa.php, (2) username parameter to login.php, or (3) ke... Read more
Affected Products : aphpkb- Published: Jan. 08, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1905
Cross-site scripting (XSS) vulnerability in the Zero Point theme 7.x-1.x before 7.x-1.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jun. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-7368
Multiple cross-site scripting (XSS) vulnerabilities in Gnew 2013.1 allow remote attackers to inject arbitrary web script or HTML via the gnew_template parameter to (1) users/profile.php, (2) articles/index.php, or (3) admin/polls.php; (4) category_id para... Read more
Affected Products : gnew- Published: Apr. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-2018
Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 8.x, 9.0x, and 9.1x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : network_node_manager_i- Published: Jul. 05, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-6294
Cross-site scripting (XSS) vulnerability in the External links click statistics (outstats) extension 0.0.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : external_links_click_statistics- Published: Oct. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-0959
Cross-site scripting (XSS) vulnerability in WebEditor/Authentication/LoginPage.aspx in IBM ENOVIA SmarTeam 5 allows remote attackers to inject arbitrary web script or HTML via the errMsg parameter.... Read more
Affected Products : enovia_smarteam- Published: Mar. 10, 2010
- Modified: Apr. 11, 2025