Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-9969 | 2025-09-19 | N/A | 7.1 HIGH | ||
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vizly Web Design Real Estate Packages allows Content Spoofing, CAPEC - 593 - Session Hijacking, CAPEC - 591 - Reflected XSS.This issue affects Real Estate Packages: before 5.1.
|
|||||
| CVE-2025-10711 | 2025-09-19 | 5.0 MEDIUM | 4.3 MEDIUM | ||
|
A vulnerability has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 20250831. This vulnerability affects unknown code of the file /index.php/sysmanage/Login. Such manipulation of the argument Name leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product is published under multiple names. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2025-10146 | 2025-09-19 | N/A | 6.1 MEDIUM | ||
|
The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter in all versions up to, and including, 3.3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
|
|||||
| CVE-2025-8664 | 2025-09-19 | N/A | 6.3 MEDIUM | ||
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Computer Systems Trade Ltd. Co. StarCities E-Municipality Management allows Cross-Site Scripting (XSS).This issue affects StarCities E-Municipality Management: before 20250825.
|
|||||
| CVE-2025-43861 | 1 Miraheze | 1 Managewiki | 2025-09-19 | N/A | 4.4 MEDIUM |
|
ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 2f177dc, ManageWiki is vulnerable to reflected or stored XSS in the review dialog. A logged-in attacker must change a form field to include a malicious payload. If that same user then opens the "Review Changes" dialog, the payload will be rendered and executed in the context of their own session. This issue has been patched in commit 2f177dc.
|
|||||
| CVE-2019-25225 | 1 Apostrophecms | 1 Sanitize-html | 2025-09-19 | N/A | 6.1 MEDIUM |
|
`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into executable code.
|
|||||
| CVE-2014-125128 | 1 Apostrophecms | 1 Sanitize-html | 2025-09-19 | N/A | 6.1 MEDIUM |
|
'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in anchor tags (`<a>`), allowing bypasses that contain different casings, whitespace characters, or hexadecimal encodings.
|
|||||
| CVE-2024-25175 | 1 Kickdler | 1 Kickdler | 2025-09-19 | N/A | 6.1 MEDIUM |
|
An issue in Kickdler before v1.107.0 allows attackers to provide an XSS payload via a HTTP response splitting attack.
|
|||||
| CVE-2024-4216 | 2 Fedoraproject, Pgadmin | 2 Fedora, Pgadmin 4 | 2025-09-19 | N/A | 7.4 HIGH |
|
pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.
|
|||||
| CVE-2025-9851 | 2025-09-19 | N/A | 6.4 MEDIUM | ||
|
The Appointmind plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appointmind_calendar' shortcode in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
|
|||||
| CVE-2025-2404 | 2025-09-19 | N/A | 4.3 MEDIUM | ||
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ubit Information Technologies STOYS allows Cross-Site Scripting (XSS).This issue affects STOYS: from 2 before 20250916.
|
|||||
| CVE-2025-52074 | 1 Phpgurukul | 1 Online Shopping Portal | 2025-09-18 | N/A | 6.1 MEDIUM |
|
PHPGURUKUL Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) due to lack of input sanitization in the quantity parameter when adding a product to the cart.
|
|||||
| CVE-2025-44593 | 1 Halo | 1 Halo | 2025-09-18 | N/A | 6.1 MEDIUM |
|
Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can trigger stored XSS vulnerabilities. This vulnerability is fixed in 2.20.13
|
|||||
| CVE-2025-44595 | 1 Halo | 1 Halo | 2025-09-18 | N/A | 6.1 MEDIUM |
|
Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}.
|
|||||
| CVE-2025-58768 | 1 Thinkinai | 1 Deepchat | 2025-09-18 | N/A | 9.6 CRITICAL |
|
DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering component, there is a risky operation of directly using `innerHTML` to set user content. Therefore, any malicious content rendered via Mermaid will directly trigger the exploit chain, leading to command execution. This vulnerability is primarily caused by a failure to fully address the existing XSS issue in the project, leading to another exploit chain. The exploit chain is consiste ...
Show More |
|||||
| CVE-2025-10590 | 1 Portabilis | 1 I-educar | 2025-09-18 | 5.0 MEDIUM | 4.3 MEDIUM |
|
A security flaw has been discovered in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file /intranet/educar_usuario_det.php. The manipulation of the argument ref_pessoa results in cross site scripting. The attack can be executed remotely. The exploit has been released to the public and may be exploited.
|
|||||
| CVE-2025-10591 | 1 Portabilis | 1 I-educar | 2025-09-18 | 4.0 MEDIUM | 3.5 LOW |
|
A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_funcao_cad.php of the component Editar Função Page. This manipulation of the argument abreviatura/tipoacao causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
|
|||||
| CVE-2025-10605 | 1 Portabilis | 1 I-educar | 2025-09-18 | 5.0 MEDIUM | 4.3 MEDIUM |
|
A security flaw has been discovered in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /agenda_preferencias.php. The manipulation of the argument tipoacao results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be exploited.
|
|||||
| CVE-2025-10606 | 1 Portabilis | 1 I-educar | 2025-09-18 | 5.0 MEDIUM | 4.3 MEDIUM |
|
A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/Configuracao/ConfiguracaoMovimentoGeral. This manipulation of the argument tipoacao causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.
|
|||||
| CVE-2025-10411 | 1 Emiloi | 1 E-logbook With Health Monitoring System For Covid-19 | 2025-09-18 | 5.0 MEDIUM | 4.3 MEDIUM |
|
A vulnerability was detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some unknown processing of the file /stc-log-keeper/check_profile.php of the component POST Request Handler. The manipulation of the argument profile_id results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.
|
|||||
| CVE-2024-0083 | 2 Microsoft, Nvidia | 2 Windows, Chatrtx | 2025-09-18 | N/A | 6.5 MEDIUM |
|
NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause a cross-site scripting error by network by running malicious scripts in users' browsers. A successful exploit of this vulnerability might lead to code execution, denial of service, and information disclosure.
|
|||||
| CVE-2025-57538 | 1 Proxmox | 1 Virtual Environment | 2025-09-18 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of Proxmox Virtual Environment (PVE) 8.4 allows an authenticated user to inject malicious input. The input is stored and executed in the context of other users' browsers when they view the affected configuration page. This can lead to arbitrary JavaScript execution.
|
|||||
| CVE-2025-57539 | 1 Proxmox | 1 Virtual Environment | 2025-09-18 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment (PVE) 8.4 allows authenticated users to store malicious input. The payload is rendered unsafely in the Web UI and executed when viewed by other users, potentially leading to session hijacking or other attacks.
|
|||||
| CVE-2025-10566 | 1 Campcodes | 1 Grocery Sales And Inventory System | 2025-09-18 | 5.0 MEDIUM | 4.3 MEDIUM |
|
A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /index.php?page=users. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
|
|||||
| CVE-2025-56289 | 1 Fabian | 1 Document Management System | 2025-09-18 | N/A | 5.4 MEDIUM |
|
code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak admin's cookie information by entering malicious XSS code in the Company field when adding files.
|
|||||
| CVE-2025-56280 | 1 Carmelo | 1 Food Ordering Review System | 2025-09-18 | N/A | 5.4 MEDIUM |
|
code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the area where users submit reservation information.
|
|||||
| CVE-2025-56276 | 1 Carmelo | 1 Food Ordering Review System | 2025-09-18 | N/A | 5.4 MEDIUM |
|
code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the registration function. An attacker enters malicious JavaScript code as a username, which triggers the XSS vulnerability when the admin views user information, resulting in the disclosure of the admin's cookie information.
|
|||||
| CVE-2025-56697 | 1 Askar634 | 1 Computer Base Test | 2025-09-18 | N/A | 6.1 MEDIUM |
|
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the /users/adminpanel/admin/home.php?page=feedbacks file of Kashipara Computer Base Test v1.0. Attackers can inject malicious scripts via the smyFeedbacks POST parameter in /users/home.php.
|
|||||
| CVE-2025-57117 | 1 Remyandrade | 1 Employee Management System | 2025-09-18 | N/A | 5.4 MEDIUM |
|
A Clickjacking vulnerability exists in Rems' Employee Management System 1.0. This flaw allows remote attackers to execute arbitrary JavaScript on the department.php page by injecting a malicious payload into the Department Name field under Add Department.
|
|||||
| CVE-2024-29154 | 1 Danielmiessler | 1 Fabric | 2025-09-18 | N/A | 7.4 HIGH |
|
danielmiessler fabric through 1.3.0 allows installer/client/gui/static/js/index.js XSS because of innerHTML mishandling, such as in htmlToPlainText.
|
|||||
| CVE-2024-28434 | 1 Twenty | 1 Twenty | 2025-09-18 | N/A | 7.6 HIGH |
|
The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution of the javascript code.
|
|||||
| CVE-2025-33008 | 1 Ibm | 2 Sterling B2b Integrator, Sterling File Gateway | 2025-09-18 | N/A | 5.4 MEDIUM |
|
IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
|
|||||
| CVE-2024-28157 | 1 Jenkins | 1 Gitbucket | 2025-09-18 | N/A | 8.0 HIGH |
|
Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
|
|||||
| CVE-2025-9656 | 1 Phpgurukul | 1 Directory Management System | 2025-09-18 | 5.0 MEDIUM | 4.3 MEDIUM |
|
A security vulnerability has been detected in PHPGurukul Directory Management System 2.0. This vulnerability affects unknown code of the file /admin/add-directory.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
|
|||||
| CVE-2025-10546 | 2025-09-18 | N/A | N/A | ||
|
This vulnerability exist in PPC 2K15X Router, due to improper input validation for the Common Gateway Interface (CGI) parameters at its web management portal. A remote attacker could exploit this vulnerability by injecting malicious JavaScript into the vulnerable parameter, leading to a reflected Cross-Site Scripting (XSS) attack on the targeted system.
|
|||||
| CVE-2025-10642 | 2025-09-18 | 4.0 MEDIUM | 3.5 LOW | ||
|
A vulnerability has been found in wangchenyi1996 chat_forum up to 80bdb92f5b460d36cab36e530a2c618acef5afd2. This impacts an unknown function of the file /q.php. Such manipulation of the argument path leads to cross site scripting. The attack may be launched remotely. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases.
|
|||||
| CVE-2025-0547 | 2025-09-18 | N/A | 4.7 MEDIUM | ||
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Software Bizmu allows Cross-Site Scripting (XSS).This issue affects Bizmu: from 2.27.0 through 20250212.
|
|||||
| CVE-2025-9992 | 2025-09-18 | N/A | 6.4 MEDIUM | ||
|
The Ghost Kit – Page Builder Blocks, Motion Effects & Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS field in all versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
|
|||||
| CVE-2025-37122 | 2025-09-18 | N/A | 6.1 MEDIUM | ||
|
A vulnerability in the web-based management interface of network access control services could allow an unauthenticated remote attacker to conduct a Reflected Cross-Site Scripting (XSS) attack. Successful exploitation could allow an attacker to execute arbitrary JavaScript code in a victim's browser in the context of the affected interface.
|
|||||
| CVE-2025-50891 | 2025-09-18 | N/A | 7.2 HIGH | ||
|
The server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijacking. NOTE: a customer does not need to take any action to update locally installed software (such as Adform Site Tracking 1.1).
|
|||||