Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-8440 | 2025-09-29 | N/A | 6.4 MEDIUM | ||
|
The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
|
|||||
| CVE-2025-57424 | 2025-09-29 | N/A | 7.3 HIGH | ||
|
A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within the LTA number profile field. An attacker can insert arbitrary JavaScript into their profile, which executes in the browser of any user viewing it, including administrators. Due to the absence of the HttpOnly flag on the session cookie, this flaw could be exploited to capture session tokens and hijack user sessions, enabling elevated access.
|
|||||
| CVE-2025-57483 | 2025-09-29 | N/A | 8.1 HIGH | ||
|
A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the vulnerable parameter.
|
|||||
| CVE-2025-6396 | 2025-09-29 | N/A | 6.1 MEDIUM | ||
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webbeyaz Website Design Website Software allows Cross-Site Scripting (XSS).This issue affects Website Software: through 2025.07.14.
|
|||||
| CVE-2025-55998 | 1 Mezereon | 1 Smart Search And Filter | 2025-09-29 | N/A | 8.1 HIGH |
|
A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into several filter parameter
|
|||||
| CVE-2024-57601 | 1 Easyappointments | 1 Easyappointments | 2025-09-29 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter.
|
|||||
| CVE-2024-51229 | 1 Pb-cms Project | 1 Pb-cms | 2025-09-29 | N/A | 8.8 HIGH |
|
Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.
|
|||||
| CVE-2024-45962 | 1 Octobercms | 1 October | 2025-09-29 | N/A | 4.7 MEDIUM |
|
October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted JavaScript to the target.
|
|||||
| CVE-2023-49453 | 1 Racktables Project | 1 Racktables | 2025-09-29 | N/A | 6.1 MEDIUM |
|
Reflected cross-site scripting (XSS) vulnerability in Racktables v0.22.0 and before, allows local attackers to execute arbitrary code and obtain sensitive information via the search component in index.php.
|
|||||
| CVE-2023-48866 | 1 Grocy Project | 1 Grocy | 2025-09-29 | N/A | 5.4 MEDIUM |
|
A Cross-Site Scripting (XSS) vulnerability in the recipe preparation component within /api/objects/recipes and note component within /api/objects/shopping_lists/ of Grocy <= 4.0.3 allows attackers to obtain the victim's cookies.
|
|||||
| CVE-2023-48200 | 1 Grocy Project | 1 Grocy | 2025-09-29 | N/A | 5.4 MEDIUM |
|
Cross Site Scripting vulnerability in Grocy v.4.0.3 allows a local attacker to execute arbitrary code and obtain sensitive information via the equipment description component within /equipment/ component.
|
|||||
| CVE-2024-10477 | 1 Pb-cms Project | 1 Pb-cms | 2025-09-29 | 3.3 LOW | 2.4 LOW |
|
A vulnerability classified as problematic was found in LinZhaoguan pb-cms up to 2.0.1. This vulnerability affects unknown code of the file /admin#permissions of the component Permission Management Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10478 | 1 Pb-cms Project | 1 Pb-cms | 2025-09-29 | 3.3 LOW | 2.4 LOW |
|
A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms up to 2.0.1. This issue affects some unknown processing of the file /admin#article/edit?id=2 of the component Edit Article Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-10479 | 1 Pb-cms Project | 1 Pb-cms | 2025-09-29 | 3.3 LOW | 2.4 LOW |
|
A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknown function of the file /admin#themes of the component Theme Management Module. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2025-5966 | 1 Zohocorp | 1 Manageengine Exchange Reporter Plus | 2025-09-29 | N/A | 8.1 HIGH |
|
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.
|
|||||
| CVE-2025-5366 | 1 Zohocorp | 1 Manageengine Exchange Reporter Plus | 2025-09-29 | N/A | 8.1 HIGH |
|
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report.
|
|||||
| CVE-2025-32427 | 1 Verbb | 1 Formie | 2025-09-29 | N/A | 5.4 MEDIUM |
|
Formie is a Craft CMS plugin for creating forms. Prior to 2.1.44, when importing a form from JSON, if the field label or handle contained malicious content, the output wasn't correctly escaped when viewing a preview of what was to be imported. As imports are undertaking primarily by users who have themselves exported the form from one environment to another, and would require direct manipulation of the JSON export, this is marked as moderate. This vulnerability will not occur unless someone deli ...
Show More |
|||||
| CVE-2025-32426 | 1 Verbb | 1 Formie | 2025-09-29 | N/A | 4.6 MEDIUM |
|
Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of an email notification, which is then rendered on the preview. There is no issue when rendering the email via normal means (a delivered email). This would require access to the form's email notification settings. This has been fixed in Formie 2.1.44.
|
|||||
| CVE-2023-48198 | 1 Grocy Project | 1 Grocy | 2025-09-29 | N/A | 5.4 MEDIUM |
|
A Cross-Site Scripting (XSS) vulnerability in the 'product description' component within '/api/stock/products' of Grocy version <= 4.0.3 allows attackers to obtain a victim's cookies.
|
|||||
| CVE-2023-48197 | 1 Grocy Project | 1 Grocy | 2025-09-29 | N/A | 5.4 MEDIUM |
|
Cross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cookies when the victim clicks on the "see QR code" function.
|
|||||
| CVE-2023-47488 | 1 Combodo | 1 Itop | 2025-09-29 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted script to the attrib_manager_id parameter in the General Information page and the id parameter in the contact page.
|
|||||
| CVE-2024-25637 | 1 Octobercms | 1 October | 2025-09-29 | N/A | 3.1 LOW |
|
October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped HTML to be reflected back. There is no impact since this vulnerability cannot be exploited through normal browser interactions. This unescaped value is only detectable when using a proxy interception tool. This issue has been patched in version 3.5.15.
|
|||||
| CVE-2025-48867 | 1 Horilla | 1 Horilla | 2025-09-29 | N/A | 4.8 MEDIUM |
|
Horilla is a free and open source Human Resource Management System (HRMS). A stored cross-site scripting (XSS) vulnerability in Horilla HRM 1.3.0 allows authenticated admin or privileged users to inject malicious JavaScript payloads into multiple fields in the Project and Task modules. These payloads persist in the database and are executed when viewed by an admin or other privileged users through the web interface. Although the issue is not exploitable by unauthenticated users, it still poses a ...
Show More |
|||||
| CVE-2025-59524 | 1 Horilla | 1 Horilla | 2025-09-29 | N/A | 6.1 MEDIUM |
|
Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, the file upload flow performs validation only in the browser and does not enforce server-side checks. An attacker can bypass the client-side validation (for example, with an intercepting proxy or by submitting a crafted request) to store an executable HTML document on the server. When an administrator or other privileged user views the uploaded file, the embedded script runs in their context and se ...
Show More |
|||||
| CVE-2025-59525 | 1 Horilla | 1 Horilla | 2025-09-29 | N/A | 6.1 MEDIUM |
|
Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, improper sanitization across the application allows XSS via uploaded SVG (and via allowed <embed>), which can be chained to execute JavaScript whenever users view impacted content (e.g., announcements). This can result in admin account takeover. This issue has been patched in version 1.4.0.
|
|||||
| CVE-2025-59832 | 1 Horilla | 1 Horilla | 2025-09-29 | N/A | 9.9 CRITICAL |
|
Horilla is a free and open source Human Resource Management System (HRMS). Prior to version 1.4.0, there is a stored XSS vulnerability in the ticket comment editor. A low-privilege authenticated user could run arbitrary JavaScript in an admin’s browser, exfiltrate the admin’s cookies/CSRF token, and hijack their session. This issue has been patched in version 1.4.0.
|
|||||
| CVE-2024-8370 | 1 Grocy Project | 1 Grocy | 2025-09-29 | 4.0 MEDIUM | 3.5 LOW |
|
A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the file /api/files/recipepictures/ of the component SVG File Upload Handler. The manipulation of the argument force_serve_as with the input picture' leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. Unfortunately, the project ma ...
Show More |
|||||
| CVE-2025-9642 | 1 Gitlab | 1 Gitlab | 2025-09-29 | N/A | 8.7 HIGH |
|
An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover.
|
|||||
| CVE-2025-59821 | 1 Dnnsoftware | 1 Dotnetnuke | 2025-09-29 | N/A | 6.5 MEDIUM |
|
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, DNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that is returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the ...
Show More |
|||||
| CVE-2025-59548 | 1 Dnnsoftware | 1 Dotnetnuke | 2025-09-29 | N/A | 6.1 MEDIUM |
|
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, specially crafted URLs to the FileBrowser are vulnerable to javascript injection, affecting any unsuspecting user clicking such link. This issue has been patched in version 10.1.0.
|
|||||
| CVE-2025-59546 | 1 Dnnsoftware | 1 Dotnetnuke | 2025-09-29 | N/A | 2.4 LOW |
|
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, administrators and content editors can set html in module titles that could include javascript which could be used for XSS based attacks. This issue has been patched in version 10.1.0.
|
|||||
| CVE-2025-59545 | 1 Dnnsoftware | 1 Dotnetnuke | 2025-09-29 | N/A | 9.0 CRITICAL |
|
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). This issue has been patched in version 10.1.0.
|
|||||
| CVE-2024-40509 | 1 Openpetra | 1 Openpetra | 2025-09-29 | N/A | 7.3 HIGH |
|
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMFinDev.asmx function.
|
|||||
| CVE-2025-59539 | 1 Dnnsoftware | 1 Dotnetnuke | 2025-09-29 | N/A | 6.3 MEDIUM |
|
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, when embedding information in the Biography field, even if that field is not rich-text, users could inject javascript code that would run in the context of the website and to any other user that can view the profile including administrators and/or superusers. This issue has been patched in version 10.1.0.
|
|||||
| CVE-2024-9188 | 1 Arista | 1 Ng Firewall | 2025-09-29 | N/A | 8.8 HIGH |
|
Specially constructed queries cause cross platform scripting leaking administrator tokens
|
|||||
| CVE-2025-4469 | 1 Senior-walter | 1 Online Student Clearance System | 2025-09-27 | 3.3 LOW | 2.4 LOW |
|
A vulnerability classified as problematic has been found in SourceCodester Online Student Clearance System 1.0. Affected is an unknown function of the file /admin/add-admin.php. The manipulation of the argument txtusername/txtfullname/txtpassword/txtpassword2 leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2025-9738 | 1 Portabilis | 1 I-educar | 2025-09-27 | 4.0 MEDIUM | 3.5 LOW |
|
A flaw has been found in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_tipo_ensino_cad.php. Executing manipulation of the argument nm_tipo can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.
|
|||||
| CVE-2025-7868 | 1 Portabilis | 1 I-educar | 2025-09-27 | 4.0 MEDIUM | 3.5 LOW |
|
A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /intranet/educar_calendario_dia_motivo_cad.php of the component Calendar Module. The manipulation of the argument Motivo/descricao results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2025-7867 | 1 Portabilis | 1 I-educar | 2025-09-27 | 4.0 MEDIUM | 3.5 LOW |
|
A vulnerability has been found in Portabilis i-Educar 2.9.0/2.10.0. This vulnerability affects unknown code of the file /intranet/agenda.php of the component Agenda Module. The manipulation of the argument novo_titulo/novo_descricao leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2025-0295 | 1 Code-projects | 1 Online Book Shop | 2025-09-27 | 4.0 MEDIUM | 3.5 LOW |
|
A vulnerability was found in code-projects Online Book Shop 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /booklist.php?subcatid=1. The manipulation of the argument subcatnm leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
|
|||||