4.8

CVSS4.0

CVE-2021-47920 - WebMO Job Manager 20.0 Cross-Site Scripting via Search Parameters

WebMO Job Manager 20.0 contains a cross-site scripting vulnerability in search parameters that allows remote attackers to inject malicious script code. Attackers can exploit the filterSearch and filterSearchType parameters to perform non-persistent attacks including session hijacking and external r…

πŸ“… Published: Feb. 1, 2026, 12:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2021-47919 - Simple CMS 2.1 Non-Persistent Cross-Site Scripting via Preview Parameter

Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Attackers can inject malicious script code through a GET request to execute arbitrary scripts and potentially hijack user sessions or perform phishing attacks.

πŸ“… Published: Feb. 1, 2026, 12:15 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

8.6

CVSS4.0

CVE-2021-47918 - Simple CMS 2.1 SQL Injection Vulnerability via Users Module

Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL commands in the users module. Attackers can exploit unvalidated input parameters in the admin.php file to compromise the database management system and web application.

πŸ“… Published: Feb. 1, 2026, 12:15 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

5.1

CVSS4.0

CVE-2021-47917 - Simple CMS 2.1 Persistent Cross-Site Scripting via User Input Parameters

Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote attackers to inject malicious script code. Attackers can exploit the newUser and editUser modules to inject persistent scripts that execute on user list preview, potentially leading t…

πŸ“… Published: Feb. 1, 2026, 12:15 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

8.6

CVSS4.0

CVE-2021-47916 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Feb. 1, 2026, 12:15 p.m. πŸ”„ Last Modified: Feb. 1, 2026, 10:37 p.m.

8.6

CVSS4.0

CVE-2021-47915 - PHP Melody 3.0 SQL Injection Vulnerability via Edit Video Parameter

PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to inject malicious SQL commands. Attackers can exploit the unvalidated 'vid' parameter to execute arbitrary database queries and potentially compromise the web applicat…

πŸ“… Published: Feb. 1, 2026, 12:15 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

5.1

CVSS4.0

CVE-2021-47914 - PHP Melody 3.0 Persistent XSS Vulnerability via Edit Video Parameter

PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that allows remote attackers to inject malicious script code. Attackers can exploit this vulnerability to execute arbitrary JavaScript, potentially leading to session hijacking,…

πŸ“… Published: Feb. 1, 2026, 12:15 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

5.1

CVSS4.0

CVE-2021-47913 - PHP Melody 3.0 Persistent Cross-Site Scripting via Video Editor

PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users to inject malicious scripts. Attackers can exploit the WYSIWYG editor to execute persistent scripts, potentially leading to session hijacking and application manipulation.

πŸ“… Published: Feb. 1, 2026, 12:15 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

5.1

CVSS4.0

CVE-2021-47912 - PHP Melody 3.0 Non-Persistent Cross-Site Scripting via Multiple Parameters

PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and user import files. Attackers can inject malicious scripts through unvalidated parameters to execute client-side attacks and potentially hijack user sessions.

πŸ“… Published: Feb. 1, 2026, 12:15 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

4.8

CVSS4.0

CVE-2021-47911 - Affiliate Pro 1.7 Reflected Cross-Site Scripting via Index Module

Affiliate Pro 1.7 contains multiple reflected cross-site scripting vulnerabilities in the index module's input fields. Attackers can inject malicious scripts through fullname, username, and email parameters to execute client-side attacks and manipulate browser requests.

πŸ“… Published: Feb. 1, 2026, 12:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 1870 of 34,919
Β« previous page Β» next page
Filters