Latest CVE Feed
-
7.5
HIGHCVE-2026-0592
A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This affects an unknown function of the file /handgunner-administrator/register_code.php of the component User Registration Handler. Performing a manipulation of t... Read more
Affected Products :- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2026-0591
A vulnerability was identified in code-projects Online Product Reservation System 1.0. The impacted element is an unknown function of the file /app/checkout/update.php of the component Cart Update Handler. Such manipulation of the argument id/qty leads to... Read more
Affected Products :- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-69089
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in autolistings Auto Listings auto-listings allows Stored XSS.This issue affects Auto Listings: from n/a through <= 2.7.1.... Read more
Affected Products : auto_listings- Published: Dec. 30, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-69088
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vidish Combo Offers WooCommerce woo-combo-offers allows DOM-Based XSS.This issue affects Combo Offers WooCommerce: from n/a through <= 4.2.... Read more
Affected Products :- Published: Dec. 30, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-69034
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Lekker lekker allows PHP Local File Inclusion.This issue affects Lekker: from n/a through <= 1.8.... Read more
Affected Products :- Published: Dec. 30, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-69033
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Filter blog-filter allows DOM-Based XSS.This issue affects Blog Filter: from n/a through <= 1.7.3.... Read more
Affected Products : blog_filter- Published: Dec. 30, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
6.8
MEDIUMCVE-2025-12513
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hosts configuration form modules) allows Stored XSS to users with high privileges. This issue affects Infra Monitoring... Read more
Affected Products :- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
6.8
MEDIUMCVE-2025-12511
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (DSM extenstio configuration modules) allows Stored XSS to user with elevated privileges. This issue affects Infra Mo... Read more
Affected Products :- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-23511
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows DOM-Based XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: ... Read more
Affected Products : the_plus_addons_for_elementor- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
9.3
CRITICALCVE-2023-53975
Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execu... Read more
Affected Products : atomcms- Published: Dec. 22, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Injection
-
5.4
MEDIUMCVE-2023-52212
Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager allows Cross Site Request Forgery.This issue affects WP Job Manager: from n/a through 2.0.0.... Read more
Affected Products :- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2023-51513
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in INTINITUM FORM Geo Controller allows DOM-Based XSS.This issue affects Geo Controller: from n/a through 8.5.2.... Read more
Affected Products : geo_controller- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2023-50897
Unrestricted Upload of File with Dangerous Type vulnerability in Meow Apps Media File Renamer allows Using Malicious Files.This issue affects Media File Renamer: from n/a through 5.7.7.... Read more
Affected Products : media_file_renamer_-_auto_\&_manual_rename- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Misconfiguration
-
7.1
HIGHCVE-2023-49186
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KlbTheme Machic Core allows DOM-Based XSS.This issue affects Machic Core: from n/a through 1.2.6.... Read more
Affected Products :- Published: Jan. 05, 2026
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
6.9
MEDIUMCVE-2022-50687
Cobian Backup 11 Gravity 11.2.0.582 contains a denial of service vulnerability in the FTP password input field that allows attackers to crash the application. Attackers can generate a specially crafted 800-byte buffer and paste it into the password field ... Read more
Affected Products : backup_11- Published: Dec. 22, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Denial of Service
-
6.4
MEDIUMCVE-2021-47738
CSZ CMS 1.2.7 contains a persistent cross-site scripting vulnerability that allows unauthorized users to embed malicious JavaScript in private messages. Attackers can send messages with script payloads in the user-agent header, which will execute when an ... Read more
Affected Products : csz_cms- Published: Dec. 23, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2021-47736
CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to c... Read more
Affected Products : cmsimple_xh- Published: Dec. 23, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Authentication
-
8.6
HIGHCVE-2021-47734
CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute arbitrary code. Attackers can leverage the vulnerability by changing the functions file path and uploading m... Read more
Affected Products : cmsimple- Published: Dec. 23, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Path Traversal
-
7.2
HIGHCVE-2021-47732
CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows attackers to inject malicious JavaScript. Attackers can place unfiltered JavaScript code that executes when users click on Page or Files ... Read more
Affected Products : cmsimple- Published: Dec. 23, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2018-25138
FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers can exploit these persistent credentials to gain unauthorized shell access and login to multiple camera in... Read more
- Published: Dec. 24, 2025
- Modified: Jan. 05, 2026
- Vuln Type: Authentication