5.3

CVSS4.0

CVE-2025-0196 - code-projects Point of Sales and Inventory Management System plist.php sql injection

A vulnerability classified as critical has been found in code-projects Point of Sales and Inventory Management System 1.0. This affects an unknown part of the file /user/plist.php. The manipulation of the argument cat leads to sql injection. It is possible to initiate the attack remotely. The explo…

πŸ“… Published: Jan. 3, 2025, 7 p.m. πŸ”„ Last Modified: Feb. 25, 2025, 10:43 p.m.

5.3

CVSS4.0

CVE-2025-0195 - code-projects Point of Sales and Inventory Management System del_product.php sql injection

A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/del_product.php. The manipulation of the argument id leads to sql injection. The attack may be launche…

πŸ“… Published: Jan. 3, 2025, 6 p.m. πŸ”„ Last Modified: Feb. 25, 2025, 10:42 p.m.

4.8

CVSS4.0

CVE-2024-56412 - PhpSpreadsheet vulnerable to bypass of the XSS sanitizer using the javascript protocol and special …

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to bypass of the cross-site scripting sanitizer using the javascript protocol and special characters. An attacker can use special characters, so that the libra…

πŸ“… Published: Jan. 3, 2025, 5:20 p.m. πŸ”„ Last Modified: March 6, 2025, 1:30 p.m.

4.8

CVSS4.0

CVE-2024-56411 - PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page …

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability of the hyperlink base in the HTML page header. The HTML page is formed without sanitizing the hyperlink base. Versions 3.7.0, …

πŸ“… Published: Jan. 3, 2025, 5:19 p.m. πŸ”„ Last Modified: March 6, 2025, 1:30 p.m.

4.8

CVSS4.0

CVE-2024-56410 - PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability in custom properties

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability in custom properties. The HTML page is generated without clearing custom properties. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 …

πŸ“… Published: Jan. 3, 2025, 5:17 p.m. πŸ”„ Last Modified: April 17, 2025, 2:35 a.m.

8.3

CVSS4.0

CVE-2024-56409 - PhpSpreadsheet vulnerable to unauthorized reflected XSS in Currency.php file

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the `Currency.php` file. Using the `/vendor/phpoffice/phpspreadsheet/samples/Wizards/NumberFormat/Currency.ph…

πŸ“… Published: Jan. 3, 2025, 5:05 p.m. πŸ”„ Last Modified: April 21, 2025, 5:14 p.m.

8.3

CVSS4.0

CVE-2024-56366 - PhpSpreadsheet vulnerable to unauthorized reflected XSS in the Accounting.php file

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the `Accounting.php` file. Using the `/vendor/phpoffice/phpspreadsheet/samples/Wizards/NumberFormat/Accountin…

πŸ“… Published: Jan. 3, 2025, 5:01 p.m. πŸ”„ Last Modified: April 21, 2025, 4:57 p.m.

8.3

CVSS4.0

CVE-2024-56365 - PhpSpreadsheet vulnerable to unauthorized reflected XSS in the constructor of the Downloader class

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the constructor of the `Downloader` class. Using the `/vendor/phpoffice/phpspreadsheet/samples/download.php` …

πŸ“… Published: Jan. 3, 2025, 4:56 p.m. πŸ”„ Last Modified: April 21, 2025, 4:57 p.m.

5.3

CVSS3.1

CVE-2025-21610 - Trix allows Cross-site Scripting via `javascript:` url in a link

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.12 are vulnerable to cross-site scripting when pasting malicious code in the link field. An attacker could trick the user to copy&paste a malicious `javascript:` URL as a link that would execute arbi…

πŸ“… Published: Jan. 3, 2025, 4:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-21609 - SiYuan has an arbitrary file deletion vulnerability

SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attacker can craft a payload to exploit this vulnerability, resul…

πŸ“… Published: Jan. 3, 2025, 4:26 p.m. πŸ”„ Last Modified: May 14, 2025, 2:39 p.m.
Total resulsts: 345144
Page 6885 of 34,515
Β« previous page Β» next page
Filters