| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and immediately stores its hash as the user's new password. The temporary password is generated using PHP rand() seeded with microtime(). Because this seed is time-based and has a limited effective search space, an attacker can generate possible reset password candidates. Since the admin login endpoint does not enforce rate limiting or account lockout, these candidates can be tested online until the correct password is found. Successful exploitation may lead to administrator account takeover. At time of publication, there are no publicly available patches. |
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS.
This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43. |
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS.
This issue affects MediaWiki ReadingLists extension: 1.46 and 1.45. |
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS).
This issue affects MediaWiki Wikistories extension: 1.46, 1.45, and 1.43. |
| Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions. |
| Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions. |
| Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS.
This issue affects JetEngine: from n/a through 3.8.15.3. |
| Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions. |
| Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions. |
| Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions. |
| Subscriber Broken Access Control in Optimole <= 4.2.14 versions. |
| Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions. |
| Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions. |
| Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. |
| Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions. |
| Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions |
| A missing authorization vulnerability in Genian SSL PNS allows an attacker to bypass multi-factor authentication by manipulating a login request parameter. |
| An unrestricted file upload vulnerability caused by insufficient file extension and integrity verification in Genian SSL PNS allows an attacker to upload a dangerous file that is not an official patch |