6.9

CVSS4.0

CVE-2026-25869 - MiniGal Nano <= 0.3.5 Path Traversal via dir Parameter

MiniGal Nano versions 0.3.5 and prior contain a path traversal vulnerability in index.php via the dir parameter. The application appends user-controlled input to the photos directory and attempts to prevent traversal by removing dot-dot sequences, but this protection can be bypassed using crafted d…

πŸ“… Published: Feb. 11, 2026, 3:40 p.m. πŸ”„ Last Modified: April 17, 2026, 8:30 p.m.

5.1

CVSS4.0

CVE-2026-25868 - MiniGal Nano <= 0.3.5 Reflected XSS via dir Parameter

MiniGal Nano version 0.3.5 and prior contain a reflected cross-site scripting (XSS) vulnerability in index.php via the dir parameter. The application constructs $currentdir from user-controlled input and embeds it into an error message without output encoding, allowing an attacker to supply HTML/Ja…

πŸ“… Published: Feb. 11, 2026, 3:34 p.m. πŸ”„ Last Modified: April 16, 2026, 5:15 p.m.

2.3

CVSS4.0

CVE-2025-12474 - libjxl: Uninitialized memory read in decoder due to incorrect optimization in patch handling

A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An incorrect optimization causes the decoder to omit populating those areas.

πŸ“… Published: Feb. 11, 2026, 3:27 p.m. πŸ”„ Last Modified: April 24, 2026, 4:42 p.m.

8.7

CVSS4.0

CVE-2026-1837 - libjxl: Out-of-bounds write in grayscale color transformation when using LCMS2

A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data. This can be done by requesting color transformation of grayscale images to another grayscale colo…

πŸ“… Published: Feb. 11, 2026, 3:19 p.m. πŸ”„ Last Modified: April 17, 2026, 8:30 p.m.

5.1

CVSS4.0

CVE-2019-25317 - Kimai 2- persistent cross-site scripting (XSS)

Kimai 2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into timesheet descriptions. Attackers can insert SVG-based XSS payloads in the description field to execute arbitrary JavaScript when the page is loaded and viewed by other users.

πŸ“… Published: Feb. 11, 2026, 2:56 p.m. πŸ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2019-25316 - GOautodial 4.0 - 'CreateEvent' Persistent Cross-Site Scripting

GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the event title parameter. Attackers can exploit the CreateEvent.php endpoint by sending crafted POST requests with XSS payloads to execute arbitrary JavaS…

πŸ“… Published: Feb. 11, 2026, 2:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2019-25315 - WP Server Log Viewer 1.0 - 'logfile' Persistent Cross-Site Scripting

WordPress Server Log Viewer 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unfiltered log file paths. Attackers can add log files with embedded XSS payloads that will execute when viewed in the WordPress admin interface.

πŸ“… Published: Feb. 11, 2026, 2:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2019-25314 - Duplicate-Post 3.2.3 - Persistent Cross-Site Scripting

Yoast Duplicate-Post WordPress Plugin 3.2.3 contains a persistent cross-site scripting vulnerability in plugin settings parameters. Attackers can inject malicious scripts into title prefix, suffix, menu order, and blacklist fields to execute arbitrary JavaScript in admin interfaces.

πŸ“… Published: Feb. 11, 2026, 2:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2019-25312 - InoERP 0.7.2 - Persistent Cross-Site Scripting

InoERP 0.7.2 contains a persistent cross-site scripting vulnerability in the comment section that allows unauthenticated attackers to inject malicious scripts. Attackers can submit comments with JavaScript payloads that execute in other users' browsers, potentially stealing cookies and session info…

πŸ“… Published: Feb. 11, 2026, 2:56 p.m. πŸ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2019-25311 - thesystem Persistent XSS

thesystem version 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through multiple server data input fields. Attackers can submit crafted script payloads in operating_system, system_owner, system_username, system_password, system_descri…

πŸ“… Published: Feb. 11, 2026, 2:56 p.m. πŸ”„ Last Modified: March 12, 2026, 6:52 p.m.
Total resulsts: 349182
Page 1680 of 34,919
Β« previous page Β» next page
Filters