Skip to content

Commit 70e2327

Browse files
Sync EUVD catalog: Mon May 11 00:50:00 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent caf6ed2 commit 70e2327

102 files changed

Lines changed: 3752 additions & 1 deletion

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2021-34781",
3+
"enisaUuid": "54e462a8-3ebf-3e03-9a7b-ebb7900fa103",
4+
"description": "Rocket LMS 1.1 contains a persistent cross-site scripting vulnerability in the support ticket module that allows authenticated users to inject malicious script code through the title parameter. Attackers can submit support tickets with embedded HTML/JavaScript payloads that execute in the browsers of other users viewing the message history, enabling session hijacking and phishing attacks.",
5+
"datePublished": "May 10, 2026, 3:31:18 PM",
6+
"dateUpdated": "May 10, 2026, 3:31:18 PM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/50677\nhttps://lms.rocket-soft.org/\nhttps://www.vulncheck.com/advisories/rocket-lms-persistent-cross-site-scripting-via-support-tickets\nhttps://nvd.nist.gov/vuln/detail/CVE-2021-47907\n",
11+
"aliases": "CVE-2021-47907\nGHSA-p5cq-w88f-fj6p\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "de62b63c-ac3b-3548-ad08-aedd252e505a",
17+
"product": {
18+
"name": "Rocket LMS"
19+
},
20+
"product_version": "1.1"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "ab8a35fd-f895-35d7-af4c-6a2364d3da14",
26+
"vendor": {
27+
"name": "RocketSoft"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2021-34783",
3+
"enisaUuid": "f3da0768-d189-3332-b23b-e9c02b3fceed",
4+
"description": "AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering JavaScript payloads into the 'icon title' field. Attackers can store XSS payloads like image tags with onerror event handlers that execute when the plugin page is viewed, affecting all users who access the plugin interface.",
5+
"datePublished": "May 10, 2026, 3:31:18 PM",
6+
"dateUpdated": "May 10, 2026, 3:31:18 PM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/50515\nhttps://accesspressthemes.com/\nhttps://wordpress.org/plugins/accesspress-social-icons/\nhttps://www.vulncheck.com/advisories/wordpress-plugin-accesspress-social-icons-stored-xss\nhttps://nvd.nist.gov/vuln/detail/CVE-2021-47910\n",
11+
"aliases": "GHSA-2383-5994-2wcp\nCVE-2021-47910\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "9a9b178b-16cf-36fd-8ca8-78c3179e1f3d",
17+
"product": {
18+
"name": "AccessPress Social Icons"
19+
},
20+
"product_version": "1.8.2"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "4dc44b34-356e-315b-ba53-6dc6c3b43885",
26+
"vendor": {
27+
"name": "Accesspressthemes"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2021-34784",
3+
"enisaUuid": "00c0243d-fa17-39f9-a88c-a46ea25a501d",
4+
"description": "Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the title parameter. Attackers can add JavaScript payloads in the title field when creating or editing sliders, which executes in the browsers of users viewing the slider on both administrative and frontend pages.",
5+
"datePublished": "May 10, 2026, 3:31:18 PM",
6+
"dateUpdated": "May 10, 2026, 3:31:18 PM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/50563\nhttps://soliloquywp.com/\nhttps://wordpress.org/plugins/soliloquy-lite/\nhttps://www.vulncheck.com/advisories/wordpress-plugin-slider-by-soliloquy-stored-xss\nhttps://nvd.nist.gov/vuln/detail/CVE-2021-47922\n",
11+
"aliases": "GHSA-x787-xpw4-5v3j\nCVE-2021-47922\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "49b33f36-44e3-3758-ae64-c569dd3b130c",
17+
"product": {
18+
"name": "Slider by Soliloquy"
19+
},
20+
"product_version": "2.6.2"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "6e44fd82-6599-343f-a616-525c74badd3a",
26+
"vendor": {
27+
"name": "Soliloquywp"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2021-34785",
3+
"enisaUuid": "e341502f-8c82-3c50-8a4e-9a5440f28642",
4+
"description": "OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSESSID cookie. Attackers can set malicious OCSESSID cookie values that the server accepts and maintains, enabling session takeover and unauthorized access to user accounts.",
5+
"datePublished": "May 10, 2026, 3:31:18 PM",
6+
"dateUpdated": "May 10, 2026, 3:31:18 PM",
7+
"baseScore": 9.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/50555\nhttps://www.opencart.com/\nhttps://www.vulncheck.com/advisories/opencart-session-fixation-via-ocsessid-cookie\nhttps://nvd.nist.gov/vuln/detail/CVE-2021-47923\n",
11+
"aliases": "CVE-2021-47923\nGHSA-5hhh-fq62-xfww\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "e6d04ad7-1dc3-3b74-b082-71fa56503a38",
17+
"product": {
18+
"name": "Opencart"
19+
},
20+
"product_version": "3.0.3.8"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "bb558b48-476a-3158-9c5a-e743f98e486c",
26+
"vendor": {
27+
"name": "Opencart"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2021-34786",
3+
"enisaUuid": "e8151e5d-4f8a-30ca-bdaf-5355e7be5003",
4+
"description": "Ultimate Product Catalog 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the price parameter. Attackers can submit POST requests to post.php with HTML/JavaScript payloads in the price field to execute arbitrary code when the product is viewed.",
5+
"datePublished": "May 10, 2026, 3:31:18 PM",
6+
"dateUpdated": "May 10, 2026, 3:31:18 PM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/50534\nhttps://www.etoilewebdesign.com\nhttps://wordpress.org/plugins/ultimate-product-catalogue/\nhttps://www.vulncheck.com/advisories/wordpress-plugin-ultimate-product-catalog-stored-xss-via-price\nhttps://nvd.nist.gov/vuln/detail/CVE-2021-47924\n",
11+
"aliases": "CVE-2021-47924\nGHSA-qwj3-2cv8-c6jp\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "de2f7096-cd21-33a6-b826-f9b40b4c4edc",
17+
"product": {
18+
"name": "Ultimate Product Catalog"
19+
},
20+
"product_version": "5.8.2"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "8cb92801-d229-349d-a2bd-cc29c4e0e7b0",
26+
"vendor": {
27+
"name": "Etoilewebdesign"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2021-34787",
3+
"enisaUuid": "8f54b7f2-b57b-36ae-b954-e0f48008ae7c",
4+
"description": "CMDBuild 3.3.2 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject arbitrary web script or HTML via crafted input in card creation and file upload endpoints. Attackers can inject XSS payloads through Employee card parameters or SVG file attachments in the classes endpoint, which execute when other users view the affected records or preview attachments.",
5+
"datePublished": "May 10, 2026, 3:31:19 PM",
6+
"dateUpdated": "May 10, 2026, 3:31:19 PM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/50527\nhttps://www.cmdbuild.org\nhttps://www.cmdbuild.org/en/download/latest-version\nhttps://www.vulncheck.com/advisories/cmdbuild-multiple-stored-cross-site-scripting\nhttps://nvd.nist.gov/vuln/detail/CVE-2021-47925\n",
11+
"aliases": "GHSA-fvcr-pgh5-37hj\nCVE-2021-47925\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "56273169-d2e4-3ff2-a2b0-1aa885c7d3d3",
17+
"product": {
18+
"name": "CMDBuild"
19+
},
20+
"product_version": "CMDBuild 3.3.2"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "ed6ad50c-73bb-3a0f-b977-d3f6f3971006",
26+
"vendor": {
27+
"name": "Cmdbuild"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2021-34788",
3+
"enisaUuid": "7d7bff72-f377-3f59-bd08-94d314cb3cb9",
4+
"description": "Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating forms with script tags in the form name field. Attackers can craft form names containing JavaScript code that executes when other logged-in users access the form management page, enabling session hijacking or credential theft.",
5+
"datePublished": "May 10, 2026, 3:31:19 PM",
6+
"dateUpdated": "May 10, 2026, 3:31:19 PM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/50524\nhttps://form2email.dwbooster.com/\nhttps://www.vulncheck.com/advisories/wordpress-contact-form-to-email-stored-xss\nhttps://nvd.nist.gov/vuln/detail/CVE-2021-47926\n",
11+
"aliases": "GHSA-94gc-c5w3-57wp\nCVE-2021-47926\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "bc74e6ac-7915-3278-ae1c-b801187f688a",
17+
"product": {
18+
"name": "Contact Form to Email"
19+
},
20+
"product_version": "1.3.24"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "70039d9a-cab2-3575-a2a5-e636bc0dd500",
26+
"vendor": {
27+
"name": "Form2Email"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2021-34789",
3+
"enisaUuid": "cec10427-0ef8-3e80-bc1d-9f4287224ffe",
4+
"description": "WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting insufficient sanitization of the forum name parameter. Attackers can submit POST requests to the admin setup page with JavaScript payloads in the wps_admin_forum_add_name parameter, which are stored and executed when the forum is accessed.",
5+
"datePublished": "May 10, 2026, 3:31:19 PM",
6+
"dateUpdated": "May 10, 2026, 3:31:19 PM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/50514\nhttp://www.wpsymposiumpro.com/\nhttps://wordpress.org/plugins/wp-symposium-pro/\nhttps://www.vulncheck.com/advisories/wordpress-plugin-wp-symposium-pro-stored-xss-via-wps-admin-forum-add-name\nhttps://nvd.nist.gov/vuln/detail/CVE-2021-47927\n",
11+
"aliases": "GHSA-rj36-m5c4-rgw9\nCVE-2021-47927\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "763f08d7-8b4e-357c-9dfe-5eac56aadb9a",
17+
"product": {
18+
"name": "WP Symposium Pro"
19+
},
20+
"product_version": "2021.10"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "0b9b8645-165a-386b-901d-97e7a7081eda",
26+
"vendor": {
27+
"name": "Wpsymposiumpro"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2021-34790",
3+
"enisaUuid": "f0666649-4071-3012-a1f8-61bb80463f39",
4+
"description": "Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the product_id parameter. Attackers can craft malicious SQL queries using time-based or content-based blind injection techniques to enumerate usernames, emails, and password reset codes from the oc_user table.",
5+
"datePublished": "May 10, 2026, 3:31:19 PM",
6+
"dateUpdated": "May 10, 2026, 3:31:19 PM",
7+
"baseScore": 8.8,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/50493\nhttps://www.opencartextensions.in/\nhttps://www.opencartextensions.in/opencart-multi-vendor-multi-seller-marketplace\nhttps://www.vulncheck.com/advisories/opencart-tmd-vendor-system-3-x-blind-sql-injection-via-product-route\nhttps://nvd.nist.gov/vuln/detail/CVE-2021-47928\n",
11+
"aliases": "GHSA-jrxv-9x2j-97hw\nCVE-2021-47928\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "574a84e4-c240-315b-be44-99d2470c4248",
17+
"product": {
18+
"name": "Extension TMD Vendor System"
19+
},
20+
"product_version": "3.0"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "77e1f19f-f66b-35e8-8f25-fe7585cd46ed",
26+
"vendor": {
27+
"name": "opencartextensions"
28+
}
29+
}
30+
]
31+
}
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"id": "EUVD-2021-34791",
3+
"enisaUuid": "6696b797-4135-3647-a157-a627bf3a6fa7",
4+
"description": "Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by entering payloads in the title field. Attackers can store JavaScript code like image tags with onerror handlers that execute when the gallery is previewed, affecting all users viewing the page.",
5+
"datePublished": "May 10, 2026, 3:31:19 PM",
6+
"dateUpdated": "May 10, 2026, 3:31:19 PM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
10+
"references": "https://www.exploit-db.com/exploits/50458\nhttp://www.filterable-portfolio.com/\nhttps://wordpress.org/plugins/fg-gallery/\nhttps://www.vulncheck.com/advisories/wordpress-plugin-filterable-portfolio-gallery-stored-xss\nhttps://nvd.nist.gov/vuln/detail/CVE-2021-47929\n",
11+
"aliases": "GHSA-4c29-8572-7xww\nCVE-2021-47929\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "8cb711d6-2de3-3b1b-87e5-06af38391c0a",
17+
"product": {
18+
"name": "Filterable Portfolio Gallery"
19+
},
20+
"product_version": "1.0"
21+
}
22+
],
23+
"enisaIdVendor": [
24+
{
25+
"id": "497418fc-007c-3d7e-98c0-42e67e5dbc72",
26+
"vendor": {
27+
"name": "Filterable-Portfolio"
28+
}
29+
}
30+
]
31+
}

0 commit comments

Comments
 (0)