5.1

CVSS4.0

CVE-2023-53918 - PodcastGenerator Stored Cross-Site Scripting via Episode Title Field

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the episode title field accessible through the episodes upload interface (episodes_upload.php). Malicious JavaScript payloads injected into episode titles execute when administrators view the episodes list page (episodes…

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

5.1

CVSS4.0

CVE-2023-53916 - Zenphoto 1.6 Stored Cross-Site Scripting via User Postal Code Field

Zenphoto 1.6 contains a stored cross-site scripting vulnerability in the user postal code field accessible through the admin-users.php interface. When administrators view user information imported as HTML, malicious JavaScript payloads injected into the postal code field execute in their browser co…

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

5.1

CVSS4.0

CVE-2023-53915 - Zenphoto 1.6 Stored Cross-Site Scripting via Album Description

Zenphoto 1.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting HTML content into album descriptions. Attackers can create albums with malicious iframe or script tags in the description field that execute when users view…

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

9.3

CVSS4.0

CVE-2023-53914 - UliCMS 2023.1 Authentication Bypass via Mass Assignment Vulnerability

UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpoint with specific parameters to generate an administrative a…

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

6.2

CVSS4.0

CVE-2023-53913 - Rukovoditel 3.3.1 CSV Injection via User Account Export

Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file.

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

8.5

CVSS4.0

CVE-2023-53912 - USB Flash Drives Control 4.1.0.0 Unquoted Service Path Privilege Escalation

USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\USB Flash Drives Control\usbcs.exe' to inject malicious execu…

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

5.1

CVSS4.0

CVE-2023-53911 - Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpt

Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert JavaScript payloads into the excerpt, which will execute when the article is viewed by other users.

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

5.1

CVSS4.0

CVE-2023-53910 - WBCE CMS 1.6.1 Stored Cross-Site Scripting via Page Content

WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by inserting script tags into page content through the WYSIWYG editor. Attackers can submit POST requests to /wbce/modules/wysiwyg/save.php with malicious script co…

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

5.1

CVSS4.0

CVE-2023-53909 - WBCE CMS 1.6.1 SVG File Content Cross-Site Scripting

WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by uploading crafted SVG files through the media manager. Attackers can upload SVG files containing script tags to the /wbce/modules/elfinder/ef/php/connector.wbce.…

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

8.7

CVSS4.0

CVE-2023-53908 - HiSecOS 04.0.01 Privilege Escalation via User Role Modification

HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a specific role value to elevate their user privileges to admini…

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.
Total resulsts: 323205
Page 27 of 32,321
Β« previous page Β» next page
Filters