Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-26 CVE-2024-43339 Cross-Site Request Forgery (CSRF) vulnerability in Webinarpress
Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress allows Cross-Site Scripting (XSS).This issue affects WebinarPress: from n/a through 1.33.20.
network
low complexity
webinarpress CWE-352
6.1
2024-08-26 CVE-2024-43340 Cross-Site Request Forgery (CSRF) vulnerability in Advancedformintegration Advanced Form Integration
Cross-Site Request Forgery (CSRF) vulnerability in Nasirahmed Advanced Form Integration.This issue affects Advanced Form Integration: from n/a through 1.89.4.
network
low complexity
advancedformintegration CWE-352
4.3
2024-08-26 CVE-2024-43356 Cross-Site Request Forgery (CSRF) vulnerability in Bobbingwide OIK
Cross-Site Request Forgery (CSRF) vulnerability in bobbingwide.This issue affects oik: from n/a through 4.12.0.
network
low complexity
bobbingwide CWE-352
4.3
2024-08-26 CVE-2024-43915 Cross-site Scripting vulnerability in Zephyr-One Zephyr Project Manager
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through .3.102.
network
low complexity
zephyr-one CWE-79
5.4
2024-08-26 CVE-2024-42906 Cross-site Scripting vulnerability in Testlink
TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file.
network
low complexity
testlink CWE-79
6.1
2024-08-26 CVE-2024-44793 Cross-site Scripting vulnerability in Gazelle Project Gazelle
A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the torrents parameter.
network
low complexity
gazelle-project CWE-79
6.1
2024-08-26 CVE-2024-44794 Cross-site Scripting vulnerability in Xiebruce Picuploader
A cross-site scripting (XSS) vulnerability in the component /master/auth/OnedriveRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error_description parameter.
network
low complexity
xiebruce CWE-79
6.1
2024-08-26 CVE-2024-44795 Cross-site Scripting vulnerability in Gazelle Project Gazelle
A cross-site scripting (XSS) vulnerability in the component /login/disabled.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.
network
low complexity
gazelle-project CWE-79
6.1
2024-08-26 CVE-2024-44796 Cross-site Scripting vulnerability in Xiebruce Picuploader
A cross-site scripting (XSS) vulnerability in the component /auth/AzureRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error_description parameter.
network
low complexity
xiebruce CWE-79
6.1
2024-08-26 CVE-2024-44797 Cross-site Scripting vulnerability in Gazelle Project Gazelle
A cross-site scripting (XSS) vulnerability in the component /managers/enable_requests.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the view parameter.
network
low complexity
gazelle-project CWE-79
6.1