Vulnerabilities
Summary — last 7 days
New vulnerabilities2,741▲ 14 vs. last week
Critical / high1,459▲ 324 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)85▼ 441 vs. last week
46 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.9) | 0.14% | — | Livejournal ShortcodeAI | 9/2/2026 | 9/3/2026 | The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Deferred | Medium (6.5) | 0.58% | — | Mediabeta WP JournalAI | 3/3/2025 | 6/17/2026 | Missing Authorization vulnerability in mediabeta WP Journal wpjournal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Journal: from n/a through <= 1.1. | |
| Deferred | Medium (6.9) | 0.45% | — | Blog Botz FOR Journal ThemeAIOpencartAI | 1/14/2025 | 6/17/2026 | A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file /index.php?route=extension/module/blog_add. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The… | |
| Analyzed | Medium (6.9) | 0.44% | — | Public Knowledge Project Open Journal Systems | 8/17/2024 | 6/17/2026 | A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login/signOut. The manipulation of the argument source with the input .example.com leads to open redirect. The attack may be launched remotely. The exploit has been… | |
| Deferred | Medium (6.5) | 0.41% | — | Matt VAN Andel Adventure JournalAI | 5/14/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt van Andel Adventure Journal allows Stored XSS.This issue affects Adventure Journal: from n/a through 1.7.2. | |
| Analyzed | Medium (4.7) | 0.44% | — | Remyandrade Workout Journal APP | 3/20/2024 | 6/17/2026 | Cross Site Scripting (XSS) vulnerability in Sourcecodester Workout Journal App 1.0 allows attackers to run arbitrary code via parameters firstname and lastname in /add-user.php. | |
| Analyzed | Medium (6.1) | 0.44% | — | Public Knowledge Project Open Journal Systems | 3/1/2024 | 6/17/2026 | A cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function. | |
| Modified | Medium (6.1) | 0.44% | — | SFU Open Journal Systems | 3/1/2024 | 6/17/2026 | A cross-site scripting (XSS) vulnerability in the Production module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function. | |
| Analyzed | Medium (5.4) | 0.41% | — | Pkp.sfu Open Journal Systems | 3/1/2024 | 6/17/2026 | A cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Publicname parameter. | |
| Analyzed | Medium (6.1) | 0.53% | — | Pkp.sfu Open Journal Systems | 3/1/2024 | 6/17/2026 | Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle component. | |
| Analyzed | Medium (6.1) | 0.52% | — | Pkp.sfu Open Journal Systems | 3/1/2024 | 6/17/2026 | Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title component. | |
| Modified | Medium (6.1) | 0.48% | — | Remyandrade Travel Journal Using PHP AND Mysql With Source Code | 2/1/2024 | 6/17/2026 | A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Share Your Moments parameter at /travel-journal/write-journal.php. | |
| Modified | Medium (6.1) | 0.46% | — | Remyandrade Travel Journal Using PHP AND Mysql With Source Code | 2/1/2024 | 6/17/2026 | A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the location parameter at /travel-journal/write-journal.php. | |
| Modified | High (7.5) | 0.28% | — | Aiven Journalpump | 12/21/2023 | 6/17/2026 | journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential information contained in the configuration if… | |
| Modified | High (8.8) | 0.23% | — | Openjournalsystems Open Journal Systems | 12/11/2023 | 6/17/2026 | A vulnerability has been discovered on OJS, that consists in a CSRF (Cross-Site Request Forgery) attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated. | |
| Modified | Medium (5.4) | 0.40% | — | SFU Open Journal Systems | 11/1/2023 | 6/17/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository pkp/ojs prior to 3.3.0-16. | |
| Modified | High (8.8) | 0.26% | — | SFU Open Journal System | 10/18/2023 | 6/17/2026 | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16. | |
| Modified | Medium (6.1) | 1.0% | — | Public Knowledge Project Open Journal Systems | 4/4/2022 | 6/17/2026 | PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers. | |
| Modified | Medium (6.1) | 6.1% | — | Public Knowledge Project Open Journal Systems | 4/1/2022 | 6/17/2026 | Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header. | |
| Modified | Medium (5.4) | 0.55% | — | Accounting Journal Management Project Accounting Journal Management | 2/24/2022 | 6/17/2026 | Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is vulnerable to XSS-Stored and PHPSESSID attacks. The malicious user can attack the system by using the already session which he has from inside and outside of the network. | |
| Modified | High (7.5) | 4.7% | — | Journal-theme Journal | 7/1/2020 | 6/17/2026 | The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors. | |
| Modified | High (8.8) | 1.4% | — | SFU Open Journal System | 12/19/2019 | 6/17/2026 | An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a crafted URL, because unserialize is used. | |
| Modified | Medium (6.1) | 1.8% | — | SFU Open Journal System | 6/12/2018 | 6/17/2026 | Cross-site scripting (XSS) vulnerability in Public Knowledge Project (PKP) Open Journal System (OJS) 3.0.0 to 3.1.1-1 allows remote attackers to inject arbitrary web script or HTML via the templates/frontend/pages/search.tpl parameter (aka the By Author field). | |
| Modified | Critical (9.8) | 1.8% | — | BD PerformaBD KLA Journal Service | 6/30/2017 | 6/17/2026 | A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Journal Service, Version 1.0.51 and prior versions. They use hard-coded passwords to access the BD Kiestra Database, which could be leveraged to compromise the confidentiality of… | |
| Modified | Medium (5.4) | 0.27% | — | Bloodjournal Blood | 10/20/2014 | 6/17/2026 | The Blood (aka com.sheridan.ash) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |