Latest CVE Feed
-
3.5
LOWCVE-2022-23072
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and c... Read more
Affected Products : recipes- Published: Jun. 21, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2023-24375
Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register (Disc... Read more
Affected Products : wordpress_social_login_and_register_\(discord\,_google\,_twitter\,_linkedin\)- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
3.5
LOWCVE-2022-23058
ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.... Read more
- Published: Jun. 22, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2024-11140
The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilter... Read more
Affected Products : real_wp_shop_lite_ajax_ecommerce_shopping_cart- Published: May. 15, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
3.5
LOWCVE-2022-46168
Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta15 on the `beta` and `tests-passed` branches, recipients of a group SMTP email could see the email addresses of all other users inside ... Read more
Affected Products : discourse- Published: Jan. 05, 2023
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-2260
Cross-site scripting (XSS) vulnerability in plugins/main/content/js/ajenti.coffee in Eugene Pankov Ajenti 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality.... Read more
Affected Products : ajenti- Published: Apr. 30, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2022-32159
In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.... Read more
Affected Products : infogami- Published: Jun. 22, 2022
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2021-33595
A address bar spoofing vulnerability was discovered in Safe Browser for iOS. Showing the legitimate URL in the address bar while loading the content from other domain. This makes the user believe that the content is served by a legit domain. A remote atta... Read more
Affected Products : safe- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2014-3544
Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via the Sky... Read more
Affected Products : moodle- Published: Jul. 29, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2022-45819
Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Maker: from n/a through 1.17.1.... Read more
Affected Products : popup_maker- Published: Dec. 13, 2024
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-1979
A vulnerability was found in Quarkus. In certain conditions related to the CI process, git credentials could be inadvertently published, which could put the git repository at risk.... Read more
Affected Products : build_of_quarkus- Published: Mar. 13, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2013-0578
The Sterling Order Management APIs in IBM Sterling Multi-Channel Fulfillment Solution 8.0 before HF128 and IBM Sterling Selling and Fulfillment Foundation 8.5 before HF93, 9.0 before HF73, 9.1.0 before FP45, and 9.2.0 before FP17, when the API tester is e... Read more
- Published: May. 10, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2020-16142
On Mercedes-Benz C Class AMG Premium Plus c220 BlueTec vehicles, the Bluetooth stack mishandles %x and %c format-string specifiers in a device name in the COMAND infotainment software.... Read more
- Published: Aug. 27, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2015-2827
Cross-site scripting (XSS) vulnerability in CA Spectrum 9.2.x and 9.3.x before 9.3 H02 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-3921
Cross-site scripting (XSS) vulnerability in contact.php in Coppermine Photo Gallery before 1.5.36 allows remote authenticated users to inject arbitrary web script or HTML via the referer parameter.... Read more
Affected Products : coppermine_photo_gallery- Published: May. 27, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-2969
Cross-site scripting (XSS) vulnerability in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving invalid characters... Read more
Affected Products : sterling_control_center- Published: Jun. 19, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-3740
Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbitrary web script or HTML via the Summary field in a ticket request to the portal page.... Read more
Affected Products : spiceworks- Published: Sep. 11, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2009-0393
Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : cpei300- Published: Feb. 03, 2009
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2015-0127
IBM Leads 7.x, 8.1.0 before 8.1.0.14, 8.2, 8.5.0 before 8.5.0.7.3, 8.6.0 before 8.6.0.8.1, 9.0.0 through 9.0.0.4, 9.1.0 before 9.1.0.6.1, and 9.1.1 before 9.1.1.0.2 does not properly restrict use of FRAME elements, which allows remote authenticated users ... Read more
Affected Products : leads- Published: Jun. 28, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-7274
Cross-site scripting (XSS) vulnerability in Wallpaper Script 3.5.0082 allows remote authenticated users to inject arbitrary web script or HTML via the title field in a wallpaper file upload.... Read more
Affected Products : wallpaperscript- Published: Jan. 08, 2014
- Modified: Apr. 11, 2025