CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2024-58319

    Last Modified: 30 Dec 2025

    A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Pages dashboard widget configuration dialog. Attackers can exploit this vulnerability to execute malicious scripts in administrative users' browsers.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2024-58318

    Last Modified: 30 Dec 2025

    A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the rich text editor component for page and form builders. Attackers can exploit this vulnerability by entering malicious URIs, potentially allowing malicious scripts to execute in users' browsers.

    Published: 18 Dec 2025
    6.9
    Medium

    CVE-2024-58317

    Last Modified: 24 Dec 2025

    A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when setting administration cookies via web.config. The vulnerability affects .NET Framework projects by incorrectly handling the 'requireSSL' attribute, potentially compromising session security and authentication state.

    Published: 18 Dec 2025
    7.1
    High

    CVE-2023-53944

    Last Modified: 7 Apr 2026

    EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root by bypassing SecurityManager restrictions. Attackers can send GET requests with encoded directory traversal sequences like /..%5c..%5c to read system files such as /windows/win.ini.

    Published: 18 Dec 2025
    6.9
    Medium

    CVE-2023-53943

    Last Modified: 7 Apr 2026

    GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. Attackers can systematically test email addresses by submitting requests to the password reset endpoint and analyzing response differences to identify valid user accounts.

    Published: 18 Dec 2025
    9.4
    Critical

    CVE-2023-53942

    Last Modified: 7 Apr 2026

    File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives to the web server. Attackers can create a custom PHP payload, upload and unzip it, and then execute arbitrary system commands through a crafted PHP script with a command parameter.

    Published: 18 Dec 2025
    9.3
    Critical

    CVE-2023-53941

    Last Modified: 7 Apr 2026

    EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by injecting malicious payloads through the app_service_control parameter. Attackers can send POST requests to /index.php?zone=settings with crafted app_service_control values to execute commands with administrative privileges.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2023-53939

    Last Modified: 7 Apr 2026

    TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the folder name parameter. Attackers can edit album folder names with script tags to execute arbitrary JavaScript when other users view the affected gallery pages.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2023-53938

    Last Modified: 7 Apr 2026

    RockMongo 1.1.7 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through multiple unencoded input parameters. Attackers can exploit the vulnerability by submitting crafted payloads in database, collection, and login parameters to execute arbitrary JavaScript in victim's browser.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2023-53936

    Last Modified: 7 Apr 2026

    Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title, potentially stealing session cookies and executing arbitrary JavaScript.

    Published: 18 Dec 2025
    5.3
    Medium

    CVE-2023-53935

    Last Modified: 15 Apr 2026

    WBiz Desk 1.2 contains a SQL injection vulnerability that allows non-admin users to manipulate database queries through the 'tk' parameter in ticket.php. Attackers can inject crafted SQL statements using UNION-based techniques to extract sensitive database information by sending malformed requests to the ticket endpoint.

    Published: 18 Dec 2025
    8.7
    High

    CVE-2023-53934

    Last Modified: 24 Dec 2025

    A denial of service vulnerability in Kentico Xperience allows attackers to launch DoS attacks via specially crafted requests to the GetResource handler. Improper input validation enables remote attackers to potentially disrupt service availability through maliciously constructed requests.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2023-53738

    Last Modified: 30 Dec 2025

    A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via page preview URLs. Attackers can exploit this vulnerability to execute arbitrary scripts in users' browsers during page preview interactions.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2023-53737

    Last Modified: 30 Dec 2025

    A stored cross-site scripting vulnerability in Kentico Xperience allows global administrators to inject malicious payloads via the Localization application. Attackers can execute scripts that could affect multiple parts of the administration interface.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2023-53736

    Last Modified: 30 Dec 2025

    A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts in the administration interface. Attackers can exploit this vulnerability to execute arbitrary scripts within the administrative context.

    Published: 18 Dec 2025
    6.9
    Medium

    CVE-2022-50686

    Last Modified: 30 Dec 2025

    An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via Portal Engine form control error messages. Detailed error messages can expose internal system information and potentially reveal implementation details to unauthorized users.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2022-50685

    Last Modified: 30 Dec 2025

    A stored cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via XML file uploads as page attachments or metafiles. Attackers can upload malicious XML files that enable stored XSS, allowing malicious scripts to execute in users' browsers.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2022-50684

    Last Modified: 30 Dec 2025

    An HTML injection vulnerability in Kentico Xperience allows attackers to inject malicious HTML values into form submission emails via unencoded form fields. Unencoded form values could enable HTML content execution in recipient email clients, potentially compromising email security.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2022-50683

    Last Modified: 30 Dec 2025

    A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form redirect URL configuration. This allows malicious scripts to execute in users' browsers through unvalidated form configuration settings.

    Published: 18 Dec 2025
    6.9
    Medium

    CVE-2022-50682

    Last Modified: 24 Dec 2025

    A CRLF injection vulnerability in Kentico Xperience allows attackers to manipulate URL query string redirects via improper encoding in the routing engine. This could enable header injection and potentially facilitate further web application attacks.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2022-50681

    Last Modified: 30 Dec 2025

    A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via administration input fields in the Rich text editor component. Attackers can exploit this vulnerability to execute arbitrary scripts in users' browsers.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2022-50680

    Last Modified: 30 Dec 2025

    A stored cross-site scripting vulnerability in Kentico Xperience allows administration users to inject malicious scripts via email marketing templates. Attackers can exploit this vulnerability to execute malicious scripts that could compromise user browsers and steal sensitive information.

    Published: 18 Dec 2025
    6.9
    Medium

    CVE-2021-47712

    Last Modified: 24 Dec 2025

    A cryptography vulnerability in Kentico Xperience allows attackers to potentially manipulate URL hash values through existing hashing mechanisms. The hotfix introduces an additional security layer to prevent hash value reuse and potential exploitation.

    Published: 18 Dec 2025
    8.7
    High

    CVE-2021-47711

    Last Modified: 24 Dec 2025

    A SQL injection vulnerability in Kentico Xperience allows authenticated editors to inject malicious SQL queries via online marketing macro method parameters. This enables unauthorized database access and potential data manipulation by exploiting macro method input validation weaknesses.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2020-36891

    Last Modified: 30 Dec 2025

    A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to upload files with spoofed Content-Type that do not match file extensions. Attackers can exploit this vulnerability by uploading malicious files with manipulated MIME types, allowing malicious scripts to execute in users' browsers.

    Published: 18 Dec 2025
    8.6
    High

    CVE-2020-36890

    Last Modified: 24 Dec 2025

    An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests. Attackers could potentially compromise global administrator accounts and invalidate security-sensitive macros by manipulating user privilege levels.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2020-36889

    Last Modified: 30 Dec 2025

    A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via error messages containing specially crafted object names. This allows malicious scripts to execute in users' browsers when administrators view error messages in the administration interface.

    Published: 18 Dec 2025
    5.3
    Medium

    CVE-2019-25230

    Last Modified: 27 Dec 2025

    An information disclosure vulnerability in Kentico Xperience allows authenticated users to view sensitive system objects through the live site widget properties dialog. Attackers can exploit this vulnerability to access unauthorized system information without proper access controls.

    Published: 18 Dec 2025
    8.7
    High

    CVE-2019-25229

    Last Modified: 24 Dec 2025

    An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions to upload arbitrary file types via MVC form file uploader components. Attackers can manipulate file names and upload potentially malicious files to the system, enabling unauthorized file uploads.

    Published: 18 Dec 2025
    5.1
    Medium

    CVE-2019-25228

    Last Modified: 27 Dec 2025

    An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. Sensitive virtual context information can be exposed to external domains through page builder interactions and link/image loading.

    Published: 18 Dec 2025
    4.1
    Medium

    CVE-2025-64400

    Last Modified: 15 Apr 2026

    Control Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. The API for creating users checks that the account requesting a user creation has `edit` on the enrollment-level user directory, but is missing a separate check that the enrollment editor has access (or belongs to) the organization that they are adding a user to.

    Published: 18 Dec 2025
    7.1
    High

    CVE-2025-67745

    Last Modified: 5 Mar 2026

    MyHoard is a daemon for creating, managing and restoring MySQL backups. Starting in version 1.0.1 and prior to version 1.3.0, in some cases, myhoard logs the whole backup info, including the encryption key. Version 1.3.0 fixes the issue. As a workaround, direct logs into /dev/null.

    Published: 18 Dec 2025
    2.1
    Low

    CVE-2025-14885

    Last Modified: 24 Dec 2025

    A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_leads.php of the component Leads Generation Module. Executing manipulation can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used.

    Published: 18 Dec 2025
    5.3
    Medium

    CVE-2025-59949

    Last Modified: 30 Dec 2025

    FreshRSS is a free, self-hostable RSS aggregator. Versions prior to 1.27.1 have a logout cross-site request forgery vulnerability that can lead to denial of service via <track src>. Version 1.27.1 patches the issue.

    Published: 18 Dec 2025
    6.8
    Medium

    CVE-2025-14739

    Last Modified: 15 Apr 2026

    Access of Uninitialized Pointer vulnerability in TP-Link WR940N and WR941ND allows local unauthenticated attackers the ability to execute DoS attack and potentially arbitrary code execution under the context of the ‘root’ user.This issue affects WR940N and WR941ND: ≤ WR940N v5 3.20.1 Build 200316, ≤ WR941ND v6 3.16.9 Build 151203.

    Published: 18 Dec 2025
    5.7
    Medium

    CVE-2025-14738

    Last Modified: 29 Jan 2026

    Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This issue affects: ≤ WA850RE V2_160527, ≤ WA850RE V3_160922.

    Published: 18 Dec 2025
    7.1
    High

    CVE-2025-14737

    Last Modified: 26 Feb 2026

    Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue affects: ≤ WA850RE V2_160527, ≤ WA850RE V3_160922.

    Published: 18 Dec 2025
    7.3
    High

    CVE-2025-14884

    Last Modified: 7 Jan 2026

    A vulnerability was detected in D-Link DIR-605 202WWB03. Affected by this issue is some unknown functionality of the component Firmware Update Service. Performing manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 18 Dec 2025
    8.9
    High

    CVE-2025-14879

    Last Modified: 24 Feb 2026

    A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange of the component HTTP Request Handler. This manipulation of the argument ssid_index causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 18 Dec 2025
    5.4
    Medium

    CVE-2025-62960

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in sparklewpthemes Construction Light construction-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Construction Light: from n/a through <= 1.6.7.

    Published: 18 Dec 2025
    5.4
    Medium

    CVE-2025-62961

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in sparklewpthemes Sparkle FSE sparkle-fse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sparkle FSE: from n/a through <= 1.0.9.

    Published: 18 Dec 2025
    5
    Medium

    CVE-2025-62998

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in WP Messiah WP AI CoPilot ai-co-pilot-for-wp allows Retrieve Embedded Sensitive Data.This issue affects WP AI CoPilot: from n/a through <= 1.2.7.

    Published: 18 Dec 2025
    5.3
    Medium

    CVE-2025-63002

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in wpforchurch Sermon Manager sermon-manager-for-wordpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sermon Manager: from n/a through <= 2.30.0.

    Published: 18 Dec 2025
    5.3
    Medium

    CVE-2025-63043

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-64235

    Last Modified: 28 Apr 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Tuturn allows Path Traversal.This issue affects Tuturn: from n/a before 3.6.

    Published: 18 Dec 2025
    9.8
    Critical

    CVE-2025-64236

    Last Modified: 28 Apr 2026

    Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse.This issue affects Tuturn: from n/a before 3.6.

    Published: 18 Dec 2025
    8.7
    High

    CVE-2025-14896

    Last Modified: 15 Apr 2026

    due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, including local file system paths, leading to exposure of sensitive information.

    Published: 18 Dec 2025
    4.3
    Medium

    CVE-2025-64282

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in RadiusTheme Radius Blocks radius-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Radius Blocks: from n/a through <= 2.2.1.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-64355

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows DOM-Based XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.12.

    Published: 18 Dec 2025
    6.5
    Medium

    CVE-2025-66058

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.17.

    Published: 18 Dec 2025