Vulnerabilities (CVE)

Filtered by CWE-79
Total 28965 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-2430 1 Matteoenna 1 Website Content In Page Or Post 2024-08-01 N/A 5.4 MEDIUM
The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
CVE-2024-29278 2024-08-01 N/A 6.5 MEDIUM
funboot v1.1 is vulnerable to Cross Site Scripting (XSS) via the title field in "create a message ."
CVE-2024-28804 2024-08-01 N/A 7.1 HIGH
An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Stored Cross-site scripting (XSS) can occur via POST.
CVE-2024-28725 2024-08-01 N/A 7.1 HIGH
Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carousel Management, and System Settings.
CVE-2024-28676 2024-08-01 N/A 6.1 MEDIUM
DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via /dede/article_edit.php.
CVE-2024-28671 2024-08-01 N/A 8.8 HIGH
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/stepselect_main.php.
CVE-2024-28402 2024-08-01 N/A 5.9 MEDIUM
TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.
CVE-2024-28157 2024-08-01 N/A 8.0 HIGH
Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
CVE-2024-27558 2024-08-01 N/A 6.1 MEDIUM
Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings.
CVE-2024-27499 2024-08-01 N/A 6.5 MEDIUM
Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.
CVE-2024-25506 2024-08-01 N/A 6.5 MEDIUM
Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control of the pm_sys_sys cookie.
CVE-2024-25219 1 Task Manager In Php With Source Code Project 1 Task Manager In Php With Source Code 2024-08-01 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Task Name parameter /TaskManager/Task.php.
CVE-2024-25208 1 Barangay Management System Project 1 Barangay Management System 2024-08-01 N/A 5.4 MEDIUM
Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name parameter.
CVE-2024-23997 1 Lukasbach 1 Yana 2024-08-01 N/A 9.6 CRITICAL
Lukas Bach yana =<1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/electron-main.ts.
CVE-2024-23995 2024-08-01 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in the column name of a database table in tabulator-popup-container.
CVE-2024-22444 1 Arubanetworks 1 Edgeconnect Sd-wan Orchestrator 2024-08-01 N/A 6.1 MEDIUM
A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victims browser in the context of the affected interface.
CVE-2024-1660 2024-08-01 N/A 4.8 MEDIUM
The Top Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2023-44855 2024-08-01 N/A 6.5 MEDIUM
Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019 allows a remote attacker to execute arbitrary code via a crafted script to the rdiag, sender, and recipients parameters of the sub_219C4 function in the acu_web file.
CVE-2023-37539 1 Hcltech 1 Domino 2024-08-01 N/A 5.4 MEDIUM
The Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. An attacker with the ability to edit documents in the catalog application/database created from this template can embed a cross site scripting attack. The attack would be activated by an end user clicking it.
CVE-2020-27478 2024-08-01 N/A 7.1 HIGH
Cross Site Scripting vulnerability found in Simplcommerce v.40734964b0811f3cbaf64b6dac261683d256f961 thru 3103357200c70b4767986544e01b19dbf11505a7 allows a remote attacker to execute arbitrary code via a crafted script to the search bar feature.