Total CVEs

138,943

Critical Severity

3,617

High Severity

12,982

Last 7 Days

962
Quick preset (or use dates below)
Clear Filters
Showing 3,241 - 3,260 of 13,528 CVEs
CVE-2020-37238 MEDIUM - 6.4

CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers can upload SVG files containing embedded JavaScript to the file manager, which executes when other a...

Vendor: Cmsmadesimple
Product: CMS Made Simple
Published: May 16, 2026
Source: NVD
CVE-2020-37237 MEDIUM - 6.4

Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers with admin credentials can inject XSS payloads in the Description field of the Add banner functionality...

Vendor: Compo
Product: Composr CMS
Published: May 16, 2026
Source: NVD
CVE-2020-37236 MEDIUM - 6.4

NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the title parameter in the news addition interface. Attackers can inject JavaScript payloads via the title field in the admin panel that exe...

Vendor: Netartmedia
Product: NewsLister
Published: May 16, 2026
Source: NVD
CVE-2020-37235 MEDIUM - 6.4

WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows authenticated users to inject malicious scripts by manipulating the Logo URL parameter. Attackers with editor, administrator, contributor, or author privileges can inject base64-encode...

Vendor: themeftc
Product: Theme Wibar
Published: May 16, 2026
Source: NVD
CVE-2020-37234 MEDIUM - 6.2

Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can paste malicious data exceeding 5000 bytes into the 'Open the following file when done' fiel...

Vendor: Internetdownloadmanager
Product: Internet Download Manager
Published: May 16, 2026
Source: NVD
CVE-2020-37233 MEDIUM - 6.4

WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the figure parameter in wp:html blocks. Attackers can inject iframe elements with event handlers like onloa...

Vendor: Wordpress
Product: Buddypress
Published: May 16, 2026
Source: NVD
CVE-2026-46719 MEDIUM - 6.5

Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections. The metric names were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.

Vendor: RRWO
Product: Net::Statsd::Lite
Published: May 16, 2026
Source: NVD
CVE-2025-4202 MEDIUM - 4.3

The Multicollab: Content Team Collaboration and Editorial Workflow plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'cf_add_comment' function in all versions up to, and including, 5.2. This makes it possible for authenticated ...

Published: May 16, 2026
Source: NVD
CVE-2026-8656 MEDIUM - 6.1

Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitization of JSON values and property names. If an application compares untrusted JSON/object data and renders annotated formatter output in the DOM, attacke...

Published: May 16, 2026
Source: NVD
CVE-2026-8681 MEDIUM - 5.3

The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to reset all plugin...

Published: May 16, 2026
Source: NVD
CVE-2026-8704 MEDIUM - 6.5

Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified.

Published: May 15, 2026
Source: NVD
CVE-2025-67031 MEDIUM - 6.3

ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnerability in the participant profile field processing subsystem. Certain field configurations accept values beginning with the prefix "func:" which are passed directly into ...

Published: May 15, 2026
Source: NVD
CVE-2026-4054 MEDIUM - 4.3

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to validate the response body of proxied images, which allows a remote attacker to enact client-side DoS via an SVG file served from an attacker-controlled origin under a non-SVG Content-Type header (e.g. image...

Vendor: mattermost
Product: mattermost_server
Published: May 15, 2026
Source: NVD
CVE-2026-46365 MEDIUM - 5.4

phpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpoint that allows any authenticated user to delete tags. Any logged-in user, including regular frontend users, can delete arbitrary tags by sending a DELETE request with a valid sess...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46363 MEDIUM - 5.4

phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that bypass sanitization through encode-decode cycles. The vulnerability allows authenticated attackers with FAQ_ADD permission to inject malicious script tags via question or answer param...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46362 MEDIUM - 6.5

phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermission() that fails to terminate execution after sending a forbidden response. Attackers can access all permission-protected admin pages by requesting their URLs as authenticated user...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46361 MEDIUM - 6.9

phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and result.answerPreview are rendered with the raw filter, disabling autoescape protection. Attackers with FAQ editor privileges can inject HTML-entity-encoded payloads that bypass html_en...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-46360 MEDIUM - 5.4

phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that limits recursive entity decoding to 5 iterations, allowing attackers to bypass sanitization. Authenticated users with FAQ_EDIT permission can upload malicious SVG files with deeply ne...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-45009 MEDIUM - 4.3

phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated ordinary users to access administrative endpoints by only checking login status instead of verifying backend privileges. Attackers with valid frontend user accounts can access sen...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD
CVE-2026-45008 MEDIUM - 6.5

phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INSTANCE_DELETE permission to delete arbitrary directories. Attackers can submit traversal sequences like https://../../../<path> in the client URL parameter to recursively delet...

Vendor: thorsten
Product: phpmyfaq
Published: May 15, 2026
Source: NVD