Latest CVE Feed
-
4.3
MEDIUMCVE-2002-1445
Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent page whose name contains the script, which is inserted into the resulting error page.... Read more
Affected Products : cern_httpd- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2013-3262
Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the p parameter.... Read more
- Published: Aug. 09, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2004-1779
Cross-site scripting (XSS) vulnerability in board.php for ThWboard before beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the lastvisited parameter.... Read more
Affected Products : thwboard_beta- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2010-4973
Cross-site scripting (XSS) vulnerability in the search feature in Campsite 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the f_search_keywords parameter. NOTE: the provenance of this information is unknown; the details are obta... Read more
Affected Products : campsite- Published: Nov. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-5825
Cross-site scripting (XSS) vulnerability in index.php in Kayako SupportSuite 3.00.32 allows remote attackers to inject arbitrary web script or HTML via the query string.... Read more
Affected Products : supportsuite- Published: Nov. 10, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2004-2699
deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter.... Read more
Affected Products : aspdotnetstorefront- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2564
Multiple cross-site scripting (XSS) vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in show.asp and (2) the title parame... Read more
Affected Products : sambar_server- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-2351
Cross-site scripting (XSS) vulnerability in GBook for Php-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) name, (2) email, (3) city, and (4) message, which do not use the <script> and <style> ... Read more
Affected Products : gbook- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4362
Cross-site scripting (XSS) vulnerability in getad.php in Diesel Paid Mail allows remote attackers to inject arbitrary web script or HTML via the ps parameter.... Read more
Affected Products : diesel_paid_mail- Published: Aug. 27, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2013-3501
Multiple cross-site scripting (XSS) vulnerabilities in GroundWork Monitor Enterprise 6.7.0 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the foundation-webapp/admin/ directory, (2) the NeDi component, or (3) the ... Read more
Affected Products : groundwork_monitor- Published: May. 08, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-54728
Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace allows Cross Site Request Forgery. This issue affects CM On Demand Search And Replace: from n/a through 1.5.2.... Read more
Affected Products : cm_on_demand_search_and_replace- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2025-55716
Missing Authorization vulnerability in VeronaLabs WP Statistics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Statistics: from n/a through 14.15.... Read more
Affected Products : wp_statistics- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2013-2314
Cross-site scripting (XSS) vulnerability in the adminAuthorization function in data/class/helper/SC_Helper_Session.php in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL associated ... Read more
- Published: May. 29, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-2694
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Express and WebLogic Server 6.1 through SP7, 7.0 through SP7, 8.1 through SP5, 9.0 GA, and 9.1 GA allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : weblogic_server- Published: May. 16, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3817
Cross-site scripting (XSS) vulnerability in the LoginToboggan module 4.7.x-1.0, 4.7.x-1.x-dev, and 5.x-1.x-dev before 20070712 for Drupal, when configured to display a "Log out" link, allows remote attackers to inject arbitrary web script or HTML via a cr... Read more
Affected Products : logintoboggan_module- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-4496
Cross-site scripting (XSS) vulnerability in search in SyntaxCMS 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.... Read more
Affected Products : syntaxcms- Published: Dec. 22, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2025-6726
The Block Editor Gallery Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the classic_gallery_slider_options() function in all versions up to, and including, 1.1.1. This makes it possible ... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2025-54702
Cross-Site Request Forgery (CSRF) vulnerability in motov.net Ebook Store allows Cross Site Request Forgery. This issue affects Ebook Store: from n/a through 5.8013.... Read more
Affected Products : ebook_store- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2011-0735
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via vectors involving a "tag script."... Read more
Affected Products : coldfusion- Published: Feb. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-54703
Cross-Site Request Forgery (CSRF) vulnerability in Prince Integrate Google Drive allows Cross Site Request Forgery. This issue affects Integrate Google Drive: from n/a through 1.5.2.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Request Forgery