CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2023-43724

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "derb6zmklgtjuhh2cn5chn2qjbm2stgmfa4.oastify.comscription[1][name]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43723

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_status_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43722

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_status_groups_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43721

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "PACKING_SLIPS_SUMMARY_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43720

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "BILLING_GENDER_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43719

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "SHIPPING_GENDER_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43718

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MSEARCH_ENABLE_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43717

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MSEARCH_HIGHLIGHT_ENABLE_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43716

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MAX_DISPLAY_NEW_PRODUCTS_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43715

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "ENTRY_FIRST_NAME_MIN_LENGTH_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43714

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "SKIP_CART_PAGE_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43713

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability, which allows attackers to inject JS via the "title" parameter, in the "/admin/admin-menu/add-submit" endpoint, which can lead to unauthorized execution of scripts in a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43712

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "access_levels_name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    7.8
    High

    CVE-2022-4956

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in Caphyon Advanced Installer 19.7. This affects an unknown part of the component WinSxS DLL Handler. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. Upgrading to version 19.7.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-240903.

    Published: 30 Sept 2023
    5.3
    Medium

    CVE-2023-5313

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic was found in phpkobo Ajax Poll Script 3.18. Affected by this vulnerability is an unknown functionality of the file ajax-poll.php of the component Poll Handler. The manipulation leads to improper enforcement of a single, unique action. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240949 was assigned to this vulnerability.

    Published: 30 Sept 2023
    3.5
    Low

    CVE-2023-5305

    Last Modified: 21 Nov 2024

    A vulnerability was found in Online Banquet Booking System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /mail.php of the component Contact Us Page. The manipulation of the argument message leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-240944.

    Published: 30 Sept 2023
    3.5
    Low

    CVE-2023-5304

    Last Modified: 21 Nov 2024

    A vulnerability has been found in Online Banquet Booking System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /book-services.php of the component Service Booking. The manipulation of the argument message leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-240943.

    Published: 30 Sept 2023
    5.5
    Medium

    CVE-2023-5321

    Last Modified: 21 Nov 2024

    Missing Authorization in GitHub repository hamza417/inure prior to build94.

    Published: 30 Sept 2023
    3.5
    Low

    CVE-2023-5303

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, was found in Online Banquet Booking System 1.0. Affected is an unknown function of the file /view-booking-detail.php of the component Account Detail Handler. The manipulation of the argument username leads to cross site scripting. It is possible to launch the attack remotely. VDB-240942 is the identifier assigned to this vulnerability.

    Published: 30 Sept 2023
    3.5
    Low

    CVE-2023-5302

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in SourceCodester Best Courier Management System 1.0. This issue affects some unknown processing of the component Manage Account Page. The manipulation of the argument First Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240941 was assigned to this vulnerability.

    Published: 30 Sept 2023
    4.7
    Medium

    CVE-2023-5301

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical was found in DedeCMS 5.7.111. This vulnerability affects the function AddMyAddon of the file album_add.php. The manipulation of the argument albumUploadFiles leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240940.

    Published: 30 Sept 2023
    6.3
    Medium

    CVE-2023-5300

    Last Modified: 21 Nov 2024

    A vulnerability classified as critical has been found in TTSPlanning up to 20230925. This affects an unknown part. The manipulation of the argument uid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240939.

    Published: 30 Sept 2023
    5.5
    Medium

    CVE-2023-5298

    Last Modified: 21 Nov 2024

    A vulnerability was found in Tongda OA 2017. It has been rated as critical. Affected by this issue is some unknown functionality of the file general/hr/recruit/requirements/delete.php. The manipulation of the argument REQUIREMENTS_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-240938 is the identifier assigned to this vulnerability.

    Published: 30 Sept 2023
    6.4
    Medium

    CVE-2023-5295

    Last Modified: 8 Apr 2026

    The Comments by Startbit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vivafbcomment' shortcode in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 30 Sept 2023
    9.9
    Critical

    CVE-2023-5201

    Last Modified: 8 Apr 2026

    The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server. This requires the [php] shortcode setting to be enabled on the vulnerable site.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43711

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "admin_firstname" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43710

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "configuration_title[1][MODULE_SHIPPING_PERCENT_TEXT_TITLE]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43709

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "configuration_title[1](MODULE)" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43708

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "configuration_title[1](MODULE_PAYMENT_SAGE_PAY_SERVER_TEXT_TITLE)" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43707

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "CatalogsPageDescriptionForm[1][name] " parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43706

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "email_templates_key" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43705

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "translation_value[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43704

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "title" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43703

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "product_info[][name]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-43702

    Last Modified: 21 Nov 2024

    Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tracking_number" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.

    Published: 30 Sept 2023
    6.1
    Medium

    CVE-2023-5320

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - DOM in GitHub repository thorsten/phpmyfaq prior to 3.1.18.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-5317

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.18.

    Published: 30 Sept 2023
    7.5
    High

    CVE-2023-5318

    Last Modified: 21 Nov 2024

    Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0.

    Published: 30 Sept 2023
    6.1
    Medium

    CVE-2023-5316

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - DOM in GitHub repository thorsten/phpmyfaq prior to 3.1.18.

    Published: 30 Sept 2023
    5.4
    Medium

    CVE-2023-5319

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.18.

    Published: 30 Sept 2023
    9.8
    Critical

    CVE-2023-5227

    Last Modified: 21 Nov 2024

    Unrestricted Upload of File with Dangerous Type in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

    Published: 30 Sept 2023
    7.5
    High

    CVE-2023-44488

    Last Modified: 21 Nov 2024

    VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.

    Published: 30 Sept 2023
    8.2
    High

    CVE-2023-5207

    Last Modified: 20 Nov 2025

    A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

    Published: 30 Sept 2023
    3.7
    Low

    CVE-2023-5297

    Last Modified: 21 Nov 2024

    A vulnerability was found in Xinhu RockOA 2.3.2. It has been classified as problematic. This affects the function start of the file task.php?m=sys|runt&a=beifen. The manipulation leads to exposure of backup file to an unauthorized control sphere. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240927.

    Published: 29 Sept 2023
    4.3
    Medium

    CVE-2023-5296

    Last Modified: 21 Nov 2024

    A vulnerability was found in Xinhu RockOA 1.1/2.3.2/15.X3amdi and classified as problematic. Affected by this issue is some unknown functionality of the file api.php?m=reimplat&a=index of the component Password Handler. The manipulation leads to weak password recovery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-240926 is the identifier assigned to this vulnerability.

    Published: 29 Sept 2023
    4.7
    Medium

    CVE-2023-5294

    Last Modified: 18 Jun 2025

    A vulnerability has been found in ECshop 4.1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/order.php. The manipulation of the argument goods_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240925 was assigned to this vulnerability.

    Published: 29 Sept 2023
    4.7
    Medium

    CVE-2023-5293

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as critical, was found in ECshop 4.1.5. Affected is an unknown function of the file /admin/leancloud.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240924.

    Published: 29 Sept 2023
    2.4
    Low

    CVE-2023-5287

    Last Modified: 21 Nov 2024

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, was found in BEECMS 4.0. This affects an unknown part of the file /admin/admin_content_tag.php?action=save_content. The manipulation of the argument tag leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240915. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 29 Sept 2023
    3.5
    Low

    CVE-2023-5286

    Last Modified: 21 Nov 2024

    A vulnerability, which was classified as problematic, has been found in SourceCodester Expense Tracker App v1. Affected by this issue is some unknown functionality of the file add_category.php of the component Category Handler. The manipulation of the argument category_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-240914 is the identifier assigned to this vulnerability.

    Published: 29 Sept 2023
    6.4
    Medium

    CVE-2023-43655

    Last Modified: 18 Jun 2025

    Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability if PHP also has `register_argc_argv` enabled in php.ini. Versions 2.6.4, 2.2.22 and 1.10.27 patch this vulnerability. Users are advised to upgrade. Users unable to upgrade should make sure `register_argc_argv` is disabled in php.ini, and avoid publishing composer.phar to the web as this is not best practice.

    Published: 29 Sept 2023