Latest CVE Feed
-
8.8
HIGHCVE-2025-4155
A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unknown part of the file /admin/edit-boat.php. The manipulation of the argument bid leads to sql injection. It is possible to initiate the ... Read more
Affected Products : boat_booking_system- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
4.7
MEDIUMCVE-2025-1749
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/voucher.... Read more
Affected Products : opencart- Published: Feb. 28, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
4.7
MEDIUMCVE-2025-1748
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/register.... Read more
Affected Products : opencart- Published: Feb. 28, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
4.7
MEDIUMCVE-2025-1747
HTML injection vulnerabilities in OpenCart versions prior to 4.1.0. These vulnerabilities could allow an attacker to modify the HTML of the victim's browser by sending a malicious URL and modifying the parameter name in /account/login.... Read more
Affected Products : opencart- Published: Feb. 28, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-1746
Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the search in the /product/search endpoint. This v... Read more
Affected Products : opencart- Published: Feb. 28, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-4156
A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/change-image.php. The manipulation of the argument ID leads to sql injection. The attack can be ini... Read more
Affected Products : boat_booking_system- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4157
A vulnerability was found in PHPGurukul Boat Booking System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/booking-details.php. The manipulation of the argument Status leads to sql injection. The attack may b... Read more
Affected Products : boat_booking_system- Published: May. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2024-13569
The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : front_end_users- Published: Apr. 22, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-46225
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Post in page for Elementor allows DOM-Based XSS. This issue affects Post in page for Elementor: from n/a through 1.0.1.... Read more
Affected Products : post_in_page_for_elementor- Published: Apr. 22, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-46226
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ferranfg MPL-Publisher allows Stored XSS. This issue affects MPL-Publisher: from n/a through 2.18.0.... Read more
- Published: Apr. 22, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-46227
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brecht Custom Related Posts allows Stored XSS. This issue affects Custom Related Posts: from n/a through 1.7.4.... Read more
Affected Products : custom_related_posts- Published: Apr. 22, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13326
The iBuildApp WordPress plugin through 0.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin... Read more
Affected Products : ibuildapp- Published: Feb. 04, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-45751
SourceCodester Web Based Pharmacy Product Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add-admin.php via the Fullname text field.... Read more
Affected Products : web-based_pharmacy_product_management_system- Published: May. 05, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2022-3363
Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7.... Read more
Affected Products : rdiffweb- EPSS Score: %0.10
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
8.8
HIGHCVE-2022-39944
In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures a JDBC EC with a MySQL data source and maliciou... Read more
Affected Products : linkis- EPSS Score: %1.19
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
8.8
HIGHCVE-2022-37202
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list... Read more
Affected Products : jfinal_cms- EPSS Score: %0.46
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
6.1
MEDIUMCVE-2022-32407
Softr v2.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via the First Name parameter under the Create A New Account module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : softr- EPSS Score: %0.11
- Published: Oct. 27, 2022
- Modified: May. 07, 2025
-
6.8
MEDIUMCVE-2022-31898
gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the ping_addr and trace_addr function parameters.... Read more
- EPSS Score: %35.86
- Published: Oct. 27, 2022
- Modified: May. 07, 2025
-
9.1
CRITICALCVE-2022-2782
In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the session token parameters.... Read more
Affected Products : octopus_server- EPSS Score: %0.17
- Published: Oct. 27, 2022
- Modified: May. 07, 2025
-
5.4
MEDIUMCVE-2024-13098
The WordPress Email Newsletter WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : wordpress_email_newsletter- Published: Feb. 01, 2025
- Modified: May. 07, 2025
- Vuln Type: Cross-Site Scripting