Vulnerabilities (CVE)

Filtered by CWE-79
Angry Yack Logo
Total 42233 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-41830 1 Kyocera 80 Ecosys M2535dn, Ecosys M2535dn Firmware, Ecosys M6526cdn and 77 more 2025-04-24 N/A 4.8 MEDIUM
Stored cross-site scripting vulnerability in Kyocera Document Solutions MFPs and printers allows a remote authenticated attacker with an administrative privilege to inject arbitrary script. Affected products/versions are as follows: TASKalfa 7550ci/6550ci, TASKalfa 5550ci/4550ci/3550ci/3050ci, TASKalfa 255c/205c, TASKalfa 256ci/206ci, ECOSYS M6526cdn/M6526cidn, FS-C2126MFP/C2126MFP+/C2026MFP/C2026MFP+, TASKalfa 8000i/6500i, TASKalfa 5500i/4500i/3500i, TASKalfa 305/255, TASKalfa 306i/256i, LS-314 ...

Show More

CVE-2023-44753 1 Mayurik 1 Online Student Management System 2025-04-24 N/A 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability fin Student Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter on the profile.php page.
CVE-2023-44040 1 Veridiumid 1 Veridiumad 2025-04-24 N/A 6.1 MEDIUM
In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker for JavaScript execution in the context of the user trying to authenticate.
CVE-2023-20249 1 Cisco 1 Telepresence Management Suite 2025-04-24 N/A 5.4 MEDIUM
A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by inserting malicious data in a specific data field in the interface. A successful exploit could allow the attacker to exe ...

Show More

CVE-2023-26688 1 Cs-cart 1 Cs-cart Multivendor 2025-04-24 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the administration interface.
CVE-2022-45990 1 Ecommerce-website Project 1 Ecommerce-website 2025-04-24 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail parameter.
CVE-2022-45769 1 Clicshopping 1 Clicshopping V3 2025-04-24 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in ClicShopping_V3 v3.402 allows attackers to execute arbitrary web scripts or HTML via a crafted URL parameter.
CVE-2022-45020 1 Rukovoditel 1 Rukovoditel 2025-04-24 N/A 8.8 HIGH
Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /rukovoditel/index.php?module=users/login. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
CVE-2022-44950 1 Rukovoditel 1 Rukovoditel 2025-04-24 N/A 5.4 MEDIUM
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
CVE-2022-44949 1 Rukovoditel 1 Rukovoditel 2025-04-24 N/A 5.4 MEDIUM
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?module=entities/fields&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Short Name field.
CVE-2022-44948 1 Rukovoditel 1 Rukovoditel 2025-04-24 N/A 5.4 MEDIUM
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?module=entities/entities_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field after clicking "Add".
CVE-2022-44947 1 Rukovoditel 1 Rukovoditel 2025-04-24 N/A 5.4 MEDIUM
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feature at /index.php?module=entities/listing_types&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Note field after clicking "Add".
CVE-2022-44946 1 Rukovoditel 1 Rukovoditel 2025-04-24 N/A 5.4 MEDIUM
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.
CVE-2022-43706 1 Stackstorm 1 Stackstorm 2025-04-24 N/A 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the Web UI of StackStorm versions prior to 3.8.0 allowed logged in users with write access to pack rules to inject arbitrary script or HTML that may be executed in Web UI for other logged in users.
CVE-2022-43556 1 Concretecms 1 Concrete Cms 2025-04-24 N/A 6.1 MEDIUM
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XSS in the text input field since the result dashboard page output is not sanitized. The Concrete CMS security team has ranked this 4.2 with CVSS v3.1 vector AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N Thanks @_akbar_jafarli_ for reporting. Remediate by updating to Concrete CMS 8.5.10 and Concrete CMS 9.1.3.
CVE-2022-43500 1 Wordpress 1 Wordpress 2025-04-24 N/A 6.1 MEDIUM
Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.
CVE-2022-43499 1 Ss-proj 1 Shirasagi 2025-04-24 N/A 5.4 MEDIUM
Stored cross-site scripting vulnerability in SHIRASAGI versions prior to v1.16.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.
CVE-2022-43497 1 Wordpress 1 Wordpress 2025-04-24 N/A 6.1 MEDIUM
Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The developer also provides new patched releases for all versions since 3.7.
CVE-2022-43487 1 Salonbookingsystem 1 Salon Booking System 2025-04-24 N/A 6.1 MEDIUM
Cross-site scripting vulnerability in Salon booking system versions prior to 7.9 allows a remote unauthenticated attacker to inject an arbitrary script.
CVE-2021-34181 1 Tomexam 1 Tomexam 2025-04-24 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in TomExam 3.0 via p_name parameter to list.thtml.
CVE-2022-46089 1 Oretnom23 1 Online Flight Booking Management System 2025-04-24 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in the add-airline form of Online Flight Booking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the airline parameter.
CVE-2025-2946 1 Pgadmin 1 Pgadmin 4 2025-04-23 N/A 9.1 CRITICAL
pgAdmin <= 9.1 is affected by a security vulnerability with Cross-Site Scripting(XSS). If attackers execute any arbitrary HTML/JavaScript in a user's browser through query result rendering, then HTML/JavaScript runs on the browser.
CVE-2024-55000 1 Mayurik 1 House Rental Management System 2025-04-23 N/A 5.4 MEDIUM
Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categories.php.
CVE-2024-56115 1 Amiro 1 Amiro.cms 2025-04-23 N/A 6.1 MEDIUM
A vulnerability in Amiro.CMS before 7.8.4 exists due to the failure to take measures to neutralize special elements. It allows remote attackers to conduct a Cross-Site Scripting (XSS) attack.
CVE-2024-43437 1 Moodle 1 Moodle 2025-04-23 N/A 5.4 MEDIUM
A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.
CVE-2024-43439 1 Moodle 1 Moodle 2025-04-23 N/A 5.4 MEDIUM
A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk.
CVE-2024-5520 1 Alkacon 1 Opencms 2025-04-23 N/A 6.4 MEDIUM
Two Cross-Site Scripting vulnerabilities have been discovered in Alkacon's OpenCMS affecting version 16, which could allow a user with sufficient privileges to create and modify web pages through the admin panel, can execute malicious JavaScript code, after inserting code in the “title” field.
CVE-2023-25836 1 Esri 1 Portal For Arcgis 2025-04-23 N/A 5.4 MEDIUM
There is a Cross-site Scripting vulnerability in Esri Portal for ArcGIS Sites in versions 10.9 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser.  The privileges required to execute this attack are low.
CVE-2023-25831 1 Esri 1 Portal For Arcgis 2025-04-23 N/A 6.1 MEDIUM
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
CVE-2023-25830 1 Esri 1 Portal For Arcgis 2025-04-23 N/A 6.1 MEDIUM
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and before which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
CVE-2022-45217 1 Book Store Management System Project 1 Book Store Management System 2025-04-23 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Level parameter under the Add New System User module.
CVE-2022-45122 1 Sixapart 1 Movable Type 2025-04-23 N/A 6.1 MEDIUM
Cross-site scripting vulnerability in Movable Type Movable Type 7 r.5301 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.5301 and earlier (Movable Type Advanced 7 Series), Movable Type 6.8.7 and earlier (Movable Type 6 Series), Movable Type Advanced 6.8.7 and earlier (Movable Type Advanced 6 Series), Movable Type Premium 1.53 and earlier, and Movable Type Premium Advanced 1.53 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.
CVE-2024-41356 1 Phpipam 1 Phpipam 2025-04-23 N/A 4.7 MEDIUM
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones-edit-network.php.
CVE-2024-41357 1 Phpipam 1 Phpipam 2025-04-23 N/A 7.1 HIGH
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
CVE-2024-41353 1 Phpipam 1 Phpipam 2025-04-23 N/A 7.1 HIGH
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php
CVE-2024-41354 1 Phpipam 1 Phpipam 2025-04-23 N/A 7.1 HIGH
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php
CVE-2024-55093 1 Phpipam 1 Phpipam 2025-04-23 N/A 5.4 MEDIUM
phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts.
CVE-2022-45916 1 Ilias 1 Ilias 2025-04-23 N/A 5.4 MEDIUM
ILIAS before 7.16 allows XSS.
CVE-2025-3788 1 Jsite 1 Jsite 2025-04-23 4.0 MEDIUM 3.5 LOW
A vulnerability was found in baseweb JSite 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /a/sys/user/save. The manipulation of the argument Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-41447 1 Alkacon 1 Opencms 2025-04-23 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the author parameter under the Create/Modify article function.