Vulnerabilities

Summary — last 7 days

New vulnerabilities2,741▲ 14 vs. last week
Critical / high1,459▲ 324 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)85▼ 441 vs. last week
–

46 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.9)0.14%—Livejournal ShortcodeAI9/2/20269/3/2026
The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
DeferredMedium (6.5)0.58%—Mediabeta WP JournalAI3/3/20256/17/2026
Missing Authorization vulnerability in mediabeta WP Journal wpjournal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Journal: from n/a through <= 1.1.
DeferredMedium (6.9)0.45%—Blog Botz FOR Journal ThemeAIOpencartAI1/14/20256/17/2026
A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file /index.php?route=extension/module/blog_add. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The…
AnalyzedMedium (6.9)0.44%—Public Knowledge Project Open Journal Systems8/17/20246/17/2026
A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login/signOut. The manipulation of the argument source with the input .example.com leads to open redirect. The attack may be launched remotely. The exploit has been…
DeferredMedium (6.5)0.41%—Matt VAN Andel Adventure JournalAI5/14/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt van Andel Adventure Journal allows Stored XSS.This issue affects Adventure Journal: from n/a through 1.7.2.
AnalyzedMedium (4.7)0.44%—Remyandrade Workout Journal APP3/20/20246/17/2026
Cross Site Scripting (XSS) vulnerability in Sourcecodester Workout Journal App 1.0 allows attackers to run arbitrary code via parameters firstname and lastname in /add-user.php.
AnalyzedMedium (6.1)0.44%—Public Knowledge Project Open Journal Systems3/1/20246/17/2026
A cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function.
ModifiedMedium (6.1)0.44%—SFU Open Journal Systems3/1/20246/17/2026
A cross-site scripting (XSS) vulnerability in the Production module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function.
AnalyzedMedium (5.4)0.41%—Pkp.sfu Open Journal Systems3/1/20246/17/2026
A cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Publicname parameter.
AnalyzedMedium (6.1)0.53%—Pkp.sfu Open Journal Systems3/1/20246/17/2026
Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle component.
AnalyzedMedium (6.1)0.52%—Pkp.sfu Open Journal Systems3/1/20246/17/2026
Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title component.
ModifiedMedium (6.1)0.48%—Remyandrade Travel Journal Using PHP AND Mysql With Source Code2/1/20246/17/2026
A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Share Your Moments parameter at /travel-journal/write-journal.php.
ModifiedMedium (6.1)0.46%—Remyandrade Travel Journal Using PHP AND Mysql With Source Code2/1/20246/17/2026
A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the location parameter at /travel-journal/write-journal.php.
ModifiedHigh (7.5)0.28%—Aiven Journalpump12/21/20236/17/2026
journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential information contained in the configuration if…
ModifiedHigh (8.8)0.23%—Openjournalsystems Open Journal Systems12/11/20236/17/2026
A vulnerability has been discovered on OJS, that consists in a CSRF (Cross-Site Request Forgery) attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated.
ModifiedMedium (5.4)0.40%—SFU Open Journal Systems11/1/20236/17/2026
Cross-site Scripting (XSS) - Stored in GitHub repository pkp/ojs prior to 3.3.0-16.
ModifiedHigh (8.8)0.26%—SFU Open Journal System10/18/20236/17/2026
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16.
ModifiedMedium (6.1)1.0%—Public Knowledge Project Open Journal Systems4/4/20226/17/2026
PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers.
ModifiedMedium (6.1)6.1%—Public Knowledge Project Open Journal Systems4/1/20226/17/2026
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.
ModifiedMedium (5.4)0.55%—Accounting Journal Management Project Accounting Journal Management2/24/20226/17/2026
Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is vulnerable to XSS-Stored and PHPSESSID attacks. The malicious user can attack the system by using the already session which he has from inside and outside of the network.
ModifiedHigh (7.5)4.7%—Journal-theme Journal7/1/20206/17/2026
The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
ModifiedHigh (8.8)1.4%—SFU Open Journal System12/19/20196/17/2026
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a crafted URL, because unserialize is used.
ModifiedMedium (6.1)1.8%—SFU Open Journal System6/12/20186/17/2026
Cross-site scripting (XSS) vulnerability in Public Knowledge Project (PKP) Open Journal System (OJS) 3.0.0 to 3.1.1-1 allows remote attackers to inject arbitrary web script or HTML via the templates/frontend/pages/search.tpl parameter (aka the By Author field).
ModifiedCritical (9.8)1.8%—BD PerformaBD KLA Journal Service6/30/20176/17/2026
A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Journal Service, Version 1.0.51 and prior versions. They use hard-coded passwords to access the BD Kiestra Database, which could be leveraged to compromise the confidentiality of…
ModifiedMedium (5.4)0.27%—Bloodjournal Blood10/20/20146/17/2026
The Blood (aka com.sheridan.ash) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.