Vulnerabilities

Summary — last 7 days

New vulnerabilities2,699▼ 343 vs. last week
Critical / high1,270▼ 197 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)208▼ 123 vs. last week
–

56 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (6.1)0.40%—Nextscripts Social Networks Auto Poster12/15/20236/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NextScripts NextScripts: Social Networks Auto-Poster allows Reflected XSS.This issue affects NextScripts: Social Networks Auto-Poster: from n/a through 4.4.2.
ModifiedHigh (7.5)1.4%—Openteknik Open Source Social Network7/25/20226/17/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an HTML injection vulnerability via the location parameter at http://ip_address/:port/ossn/home.
ModifiedMedium (5.4)1.1%💥 PoCOpenteknik Open Source Social Network7/25/20226/17/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Group Timeline module.
ModifiedHigh (7.2)2.1%—Openteknik Open Source Social Network7/25/20226/17/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/administrator/com_installer. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. Note: The project owner believes this is intended behavior…
ModifiedMedium (4.8)0.89%—Openteknik Open Source Social Network7/25/20226/17/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the SitePages module.
ModifiedMedium (5.4)1.1%💥 PoCOpenteknik Open Source Social Network7/25/20226/17/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the News Feed module.
ModifiedMedium (5.4)1.1%💥 PoCOpenteknik Open Source Social Network7/25/20226/17/2026
OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Users Timeline module.
ModifiedMedium (5.4)0.50%—Simple Social Networking Site Project Simple Social Networking Site5/24/20226/17/2026
Simple Social Networking Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /sns/classes/Users.php?f=save, firstname.
ModifiedHigh (7.2)0.97%—Simple Social Networking Site Project Simple Social Networking Site5/13/20226/17/2026
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=user/manage_user&id=.
ModifiedHigh (7.2)0.97%—Simple Social Networking Site Project Simple Social Networking Site5/13/20226/17/2026
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=posts/view_post&id=.
ModifiedHigh (7.2)0.97%—Simple Social Networking Site Project Simple Social Networking Site5/13/20226/17/2026
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/members/view_member.php?id=.
ModifiedMedium (6.5)0.87%—Simple Social Networking Site Project Simple Social Networking Site5/13/20226/17/2026
Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_img.
ModifiedMedium (6.5)0.53%—Nextscripts Social Networks Auto Poster2/1/20226/17/2026
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker to make a logged in admin delete arbitrary posts via a CSRF attack
ModifiedMedium (6.1)1.3%—Nextscripts Social Networks Auto Poster2/1/20226/17/2026
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting issue
ModifiedMedium (6.1)0.87%—Nextscripts Social Networks Auto Poster11/1/20216/17/2026
The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $_REQUEST['page'] parameter which is echoed out on inc/nxs_class_snap.php by supplying the appropriate value 'nxssnap-post' to load the page in $_GET['page'] along with malicious JavaScript…
ModifiedMedium (5.9)3.8%💥 PoCOpensource-socialnetwork Open Source Social Network3/30/20206/17/2026
An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the SiteKey to insert…
ModifiedCritical (9.8)1.4%—Social Network Project Social Network8/26/20196/17/2026
Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php.
ModifiedMedium (5.3)1.5%—Humhub Social Network KIT7/29/20196/17/2026
HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Network Kits (including self-hosted ones) by brute-forcing the username after the /u/ initial URI substring, aka Response Discrepancy Information Exposure.
ModifiedCritical (9.8)3.6%—Ambittechnologies Itech B2B ScriptAmbittechnologies Itech Business Networking ScriptAmbittechnologies Itech Caregiver ScriptAmbittechnologies Itech Classifieds Script+85/9/20196/17/2026
Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i…
ModifiedMedium (6.1)1.3%—Nextscripts Social Networks Auto Poster3/22/20196/17/2026
The social-networks-auto-poster-facebook-twitter-g plugin before 4.2.8 for WordPress has wp-admin/admin.php?page=nxssnap-reposter&action=edit item XSS.
ModifiedCritical (9.8)10%💥 PoCDesignchemical Social Network Tabs3/21/20196/17/2026
The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover.
ModifiedHigh (7.5)2.5%—Oracle Social Network4/24/20176/17/2026
Vulnerability in the Oracle Social Network component of Oracle Fusion Middleware (subcomponent: Android Client). The supported version that is affected is prior to 11.1.12.0.0 (17019101). Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Social…
ModifiedMedium (5.4)0.27%—Freediyhomeimprovement Social Networking9/18/20146/17/2026
The Social Networking (aka com.wSocialNetworkingSites) application 0.33.13320.99980 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModifiedHigh (7.5)1.9%—Scripte24shop Social Network Community10/25/20126/16/2026
SQL injection vulnerability in user.php in Social Network Community 2 allows remote attackers to execute arbitrary SQL commands via the userId parameter.
ModifiedHigh (7.5)7.1%💥 ExploitPangramsoft Pointter PHP Micro-blogging Social Network12/22/20106/16/2026
Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies.