5.1

CVSS4.0

CVE-2023-53938 - RockMongo 1.1.7 Stored Cross-Site Scripting Vulnerability via Multiple Parameters

RockMongo 1.1.7 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through multiple unencoded input parameters. Attackers can exploit the vulnerability by submitting crafted payloads in database, collection, and login parameters to execute arbitra…

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

5.1

CVSS4.0

CVE-2023-53936 - Cameleon CMS 2.7.4 Authenticated Persistent Cross-Site Scripting via Post Creation

Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title, potentially stealing sessi…

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

5.3

CVSS4.0

CVE-2023-53935 - WBiz Desk 1.2 SQL Injection Vulnerability via ticket.php Parameter

WBiz Desk 1.2 contains a SQL injection vulnerability that allows non-admin users to manipulate database queries through the 'tk' parameter in ticket.php. Attackers can inject crafted SQL statements using UNION-based techniques to extract sensitive database information by sending malformed requests …

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

8.7

CVSS4.0

CVE-2023-53934 - Kentico Xperience <= 12.0.98 GetResource Handler Denial of Service

A denial of service vulnerability in Kentico Xperience allows attackers to launch DoS attacks via specially crafted requests to the GetResource handler. Improper input validation enables remote attackers to potentially disrupt service availability through maliciously constructed requests.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

5.1

CVSS4.0

CVE-2023-53738 - Kentico Xperience <= 13.0.109 Page Preview Reflected XSS

A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via page preview URLs. Attackers can exploit this vulnerability to execute arbitrary scripts in users' browsers during page preview interactions.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

2.4

CVSS4.0

CVE-2023-53737 - Kentico Xperience <= 13.0.101 Localization Application Stored XSS

A stored cross-site scripting vulnerability in Kentico Xperience allows global administrators to inject malicious payloads via the Localization application. Attackers can execute scripts that could affect multiple parts of the administration interface.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

5.1

CVSS4.0

CVE-2023-53736 - Kentico Xperience <= 13.0.120 Administration Interface Reflected XSS

A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts in the administration interface. Attackers can exploit this vulnerability to execute arbitrary scripts within the administrative context.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

6.9

CVSS4.0

CVE-2022-50686 - Kentico Xperience <= 12.0 Portal Engine Form Control Information Disclosure

An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via Portal Engine form control error messages. Detailed error messages can expose internal system information and potentially reveal implementation details to unauthorized users.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

5.1

CVSS4.0

CVE-2022-50685 - Kentico Xperience <= 13.0.56 File Upload Stored XSS

A stored cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via XML file uploads as page attachments or metafiles. Attackers can upload malicious XML files that enable stored XSS, allowing malicious scripts to execute in users' browsers.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.

5.1

CVSS4.0

CVE-2022-50684 - Kentico Xperience <= 13.0.71 Form Emails HTML Injection

An HTML injection vulnerability in Kentico Xperience allows attackers to inject malicious HTML values into form submission emails via unencoded form fields. Unencoded form values could enable HTML content execution in recipient email clients, potentially compromising email security.

πŸ“… Published: Dec. 18, 2025, 7:53 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:53 p.m.
Total resulsts: 323384
Page 8 of 32,339
Β« previous page Β» next page
Filters