Total
39143 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2025-59012 | 1 Wordpress | 1 Wordpress | 2025-09-29 | 7.1 High |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Traveler allows Reflected XSS. This issue affects Traveler: from n/a through n/a. | ||||
CVE-2025-58917 | 3 Nick Verwymeren, Woocommerce, Wordpress | 3 Quantities And Units For Woocommerce, Woocommerce, Wordpress | 2025-09-29 | 6.5 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick Verwymeren Quantities and Units for WooCommerce allows Stored XSS. This issue affects Quantities and Units for WooCommerce: from n/a through 1.0.13. | ||||
CVE-2025-60040 | 2 Fkrauthan, Wordpress | 2 Wp-mpdf, Wordpress | 2025-09-29 | 6.5 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fkrauthan wp-mpdf allows Stored XSS. This issue affects wp-mpdf: from n/a through 3.9.1. | ||||
CVE-2025-60101 | 2 Woostify, Wordpress | 2 Woostify Theme, Wordpress | 2025-09-29 | 5.9 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Woostify Woostify allows Stored XSS. This issue affects Woostify: from n/a through 2.4.2. | ||||
CVE-2025-60104 | 2 Jordy Meow, Wordpress | 2 Gallery Custom Links, Wordpress | 2025-09-29 | 5.9 Medium |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Gallery Custom Links allows Stored XSS. This issue affects Gallery Custom Links: from n/a through 2.2.5. | ||||
CVE-2024-40500 | 2 I-librarian, Scilico | 2 I-librarian, I-librarian | 2025-09-29 | 8.8 High |
Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute arbitrary code via the search function in the import component. | ||||
CVE-2023-49453 | 2 Dedecms, Racktables Project | 2 Dedecms, Racktables | 2025-09-29 | 6.1 Medium |
Reflected cross-site scripting (XSS) vulnerability in Racktables v0.22.0 and before, allows local attackers to execute arbitrary code and obtain sensitive information via the search component in index.php. | ||||
CVE-2023-48866 | 1 Grocy Project | 1 Grocy | 2025-09-29 | 5.4 Medium |
A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/shopping_lists/ of Grocy <= 4.0.3 allows attackers to obtain the victim's cookies. | ||||
CVE-2023-48200 | 1 Grocy Project | 1 Grocy | 2025-09-29 | 5.4 Medium |
Cross Site Scripting vulnerability in Grocy v.4.0.3 allows a local attacker to execute arbitrary code and obtain sensitive information via the equipment description component within /equipment/ component. | ||||
CVE-2024-10477 | 1 Pb-cms Project | 1 Pb-cms | 2025-09-29 | 2.4 Low |
A vulnerability classified as problematic was found in LinZhaoguan pb-cms up to 2.0.1. This vulnerability affects unknown code of the file /admin#permissions of the component Permission Management Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-10478 | 1 Pb-cms Project | 1 Pb-cms | 2025-09-29 | 2.4 Low |
A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms up to 2.0.1. This issue affects some unknown processing of the file /admin#article/edit?id=2 of the component Edit Article Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2024-10479 | 1 Pb-cms Project | 1 Pb-cms | 2025-09-29 | 2.4 Low |
A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknown function of the file /admin#themes of the component Theme Management Module. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2025-5966 | 1 Zohocorp | 1 Manageengine Exchange Reporter Plus | 2025-09-29 | 8.1 High |
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report. | ||||
CVE-2025-5366 | 1 Zohocorp | 1 Manageengine Exchange Reporter Plus | 2025-09-29 | 8.1 High |
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report. | ||||
CVE-2025-32427 | 1 Verbb | 1 Formie | 2025-09-29 | 5.4 Medium |
Formie is a Craft CMS plugin for creating forms. Prior to 2.1.44, when importing a form from JSON, if the field label or handle contained malicious content, the output wasn't correctly escaped when viewing a preview of what was to be imported. As imports are undertaking primarily by users who have themselves exported the form from one environment to another, and would require direct manipulation of the JSON export, this is marked as moderate. This vulnerability will not occur unless someone deliberately tampers with the export. This vulnerability is fixed in 2.1.44. | ||||
CVE-2025-32426 | 1 Verbb | 1 Formie | 2025-09-29 | 4.6 Medium |
Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of an email notification, which is then rendered on the preview. There is no issue when rendering the email via normal means (a delivered email). This would require access to the form's email notification settings. This has been fixed in Formie 2.1.44. | ||||
CVE-2023-48198 | 1 Grocy Project | 1 Grocy | 2025-09-29 | 5.4 Medium |
A Cross-Site Scripting (XSS) vulnerability in the 'product description' component within '/api/stock/products' of Grocy version <= 4.0.3 allows attackers to obtain a victim's cookies. | ||||
CVE-2023-48197 | 1 Grocy Project | 1 Grocy | 2025-09-29 | 5.4 Medium |
Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cookies when the victim clicks on the "see QR code" function. | ||||
CVE-2023-47488 | 1 Combodo | 1 Itop | 2025-09-29 | 6.1 Medium |
Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact page. | ||||
CVE-2024-25637 | 1 Octobercms | 1 October | 2025-09-29 | 3.1 Low |
October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped HTML to be reflected back. There is no impact since this vulnerability cannot be exploited through normal browser interactions. This unescaped value is only detectable when using a proxy interception tool. This issue has been patched in version 3.5.15. |