Latest CVE Feed
-
4.9
MEDIUMCVE-2025-46655
CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of different-origin file storage, such as AWS S3. NOTE: it can be considered a user error i... Read more
Affected Products : codimd- Published: Apr. 26, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
3.1
LOWCVE-2025-46653
Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only t... Read more
Affected Products : formidable- Published: Apr. 26, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-3059
Vulnerability in Drupal Profile Private.This issue affects Profile Private: *.*.... Read more
Affected Products :- Published: Mar. 31, 2025
- Modified: Apr. 29, 2025
-
6.1
MEDIUMCVE-2025-31697
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Formatter Suite allows Cross-Site Scripting (XSS).This issue affects Formatter Suite: from 0.0.0 before 2.1.0.... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-31696
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal RapiDoc OAS Field Formatter allows Cross-Site Scripting (XSS).This issue affects RapiDoc OAS Field Formatter: from 0.0.0 before 1.0.1.... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-31695
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Link field display mode formatter allows Cross-Site Scripting (XSS).This issue affects Link field display mode formatter: from 0.0.0 before 1.6.0.... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-31694
Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0.... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-31691
Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: from 0.0.0 before 2.1.0.... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-31690
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Cache Utility allows Cross Site Request Forgery.This issue affects Cache Utility: from 0.0.0 before 1.2.1.... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.1
HIGHCVE-2025-31689
Cross-Site Request Forgery (CSRF) vulnerability in Drupal General Data Protection Regulation allows Cross Site Request Forgery.This issue affects General Data Protection Regulation: from 0.0.0 before 3.0.1, from 3.1.0 before 3.1.2.... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.8
MEDIUMCVE-2025-31688
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Configuration Split allows Cross Site Request Forgery.This issue affects Configuration Split: from 0.0.0 before 1.10.0, from 2.0.0 before 2.0.2.... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2025-31687
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal SpamSpan filter allows Cross-Site Scripting (XSS).This issue affects SpamSpan filter: from 0.0.0 before 3.2.1.... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-31686
Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10.... Read more
Affected Products : open_social- Published: Mar. 31, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2025-31685
Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10.... Read more
Affected Products : open_social- Published: Mar. 31, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authorization
-
6.8
MEDIUMCVE-2025-31684
Cross-Site Request Forgery (CSRF) vulnerability in Drupal OAuth2 Client allows Cross Site Request Forgery.This issue affects OAuth2 Client: from 0.0.0 before 4.1.3.... Read more
Affected Products : drupal- Published: Mar. 31, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.4
MEDIUMCVE-2024-53636
An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the filePath parameter.... Read more
Affected Products :- Published: Apr. 26, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Misconfiguration
-
4.8
MEDIUMCVE-2022-45015
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Footer field.... Read more
Affected Products : wbce_cms- EPSS Score: %0.12
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
4.8
MEDIUMCVE-2022-45014
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Header field.... Read more
Affected Products : wbce_cms- EPSS Score: %0.12
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
4.8
MEDIUMCVE-2022-45013
A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Section Header field.... Read more
Affected Products : wbce_cms- EPSS Score: %0.12
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
4.8
MEDIUMCVE-2022-45012
A cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Source field.... Read more
Affected Products : wbce_cms- EPSS Score: %0.12
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025