| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Improper Control of Interaction Frequency vulnerability in Pusula Communication, IT, and Internet Industry and Trade Co. Ltd. Expert Mail allows Brute Force.
This issue affects Expert Mail: through 2026-09-18. |
| A flaw has been found in imgproxy up to 4.0.17. Affected by this vulnerability is the function sanitizeElement of the file processing/svg/svg.go of the component SVG Handler. Executing a manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akıllı Ticaret Software Technologies Ltd. Co. E-Commerce Pack allows Reflected XSS.
This issue affects E-Commerce Pack: through 2026-10-06. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. |
| A vulnerability was identified in SourceCodester Simple Student Information System 1.0. This issue affects some unknown processing of the file /register.php of the component Profile Field Handler. The manipulation of the argument firstname/lastname leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used. |
| Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions. |
| Unauthenticated Cross Site Scripting (XSS) in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.0.6 versions. |
| Unauthenticated Cross Site Scripting (XSS) in EduMall <= 4.5.3 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Contact Form to DB by BestWebSoft <= 1.7.6 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Database for CF7 <= 1.2.6 versions. |
| Subscriber Cross Site Scripting (XSS) in WC Fields Factory <= 4.1.12 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Lumise Product Designer <= 2.1.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in HTTP Requests Manager <= 1.3.11 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WPLMS <= 4.972 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Mapster WP Maps <= 2.0.4 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Frontend File Manager <= 23.6 versions. |
| Unauthenticated Cross Site Scripting (XSS) in SUMO Affiliates Pro <= 11.7.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Smart Forms <= 2.6.104 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WP User Frontend Pro <= 4.2.13 versions. |
| Subscriber Cross Site Scripting (XSS) in Ohio Extra <= 3.6.8 versions. |