Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-31857 | 1 Incsub | 1 Forminator | 2025-04-04 | N/A | 5.4 MEDIUM |
|
Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote attacker may obtain user information etc. and alter the page contents on the user's web browser.
|
|||||
| CVE-2023-20248 | 1 Cisco | 1 Telepresence Management Suite | 2025-04-04 | N/A | 5.4 MEDIUM |
|
A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by inserting malicious data in a specific data field in the interface. A successful exploit could allow the attacker to exe ...
Show More |
|||||
| CVE-2024-9900 | 1 Mudler | 1 Localai | 2025-04-04 | N/A | 6.1 MEDIUM |
|
mudler/localai version v2.21.1 contains a Cross-Site Scripting (XSS) vulnerability in its search functionality. The vulnerability arises due to improper sanitization of user input, allowing the injection and execution of arbitrary JavaScript code. This can lead to the execution of malicious scripts in the context of the victim's browser, potentially compromising user sessions, stealing session cookies, redirecting users to malicious websites, or manipulating the DOM.
|
|||||
| CVE-2023-23491 | 1 Fullworksplugins | 1 Quick Event Manager | 2025-04-03 | N/A | 6.1 MEDIUM |
|
The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.
|
|||||
| CVE-2023-22373 | 1 Contec | 1 Conprosys Hmi System | 2025-04-03 | N/A | 5.4 MEDIUM |
|
Cross-site scripting vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to inject an arbitrary script and obtain the sensitive information.
|
|||||
| CVE-2022-4650 | 1 Hasthemes | 1 Hashbar | 2025-04-03 | N/A | 5.4 MEDIUM |
|
The HashBar WordPress plugin before 1.3.6 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
|
|||||
| CVE-2022-4235 | 1 Rushstreetinteractive | 1 Rushbet | 2025-04-03 | N/A | 5.4 MEDIUM |
|
RushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious application. This is possible because the application exposes an activity and does not properly validate the data it receives.
|
|||||
| CVE-2022-46888 | 1 Nexusphp | 1 Nexusphp | 2025-04-03 | N/A | 6.1 MEDIUM |
|
Multiple reflective cross-site scripting (XSS) vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to inject arbitrary web script or HTML via the secret parameter in /login.php; q parameter in /user-ban-log.php; query parameter in /log.php; text parameter in /moresmiles.php; q parameter in myhr.php; or id parameter in /viewrequests.php.
|
|||||
| CVE-2024-12852 | 1 Wedevs | 1 Happy Addons For Elementor | 2025-04-03 | N/A | 6.4 MEDIUM |
|
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
|
|||||
| CVE-2025-23108 | 1 Mozilla | 1 Firefox | 2025-04-03 | N/A | 4.3 MEDIUM |
|
Opening Javascript links in a new tab via long-press in the Firefox iOS client could result in a malicious script spoofing the URL of the new tab. This vulnerability affects Firefox for iOS < 134.
|
|||||
| CVE-2024-57488 | 1 Code-projects | 1 Online Car Rental System | 2025-04-03 | N/A | 6.5 MEDIUM |
|
Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter in /admin/edit-vehicle.php.
|
|||||
| CVE-2025-25625 | 1 Fs | 2 S3150-8t2f, S3150-8t2f Firmware | 2025-04-03 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting vulnerability exists in FS model S3150-8T2F switches running firmware s3150-8t2f-switch-fsos-220d_118101 and web firmware v2.2.2, which allows an authenticated web interface user to bypass input filtering on user names, and stores un-sanitized HTML and Javascript on the device. Pages which then present the user name without encoding special characters will then cause the injected code to be parsed by the browsers of other users accessing the web interface.
|
|||||
| CVE-2022-46889 | 1 Nexusphp | 1 Nexusphp | 2025-04-03 | N/A | 5.4 MEDIUM |
|
A persistent cross-site scripting (XSS) vulnerability in NexusPHP before 1.7.33 allows remote authenticated attackers to permanently inject arbitrary web script or HTML via the title parameter used in /subtitles.php.
|
|||||
| CVE-2024-10560 | 1 10web | 1 Form Maker | 2025-04-03 | N/A | 3.5 LOW |
|
The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
|
|||||
| CVE-2024-55029 | 1 Nasa | 1 Fprime | 2025-04-03 | N/A | 6.1 MEDIUM |
|
NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
|
|||||
| CVE-2025-28010 | 1 Modx | 1 Modx | 2025-04-03 | N/A | 5.4 MEDIUM |
|
A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.
|
|||||
| CVE-2024-12892 | 1 Code-projects | 1 Online Exam Mastering System | 2025-04-03 | 4.0 MEDIUM | 3.5 LOW |
|
A vulnerability classified as problematic was found in code-projects Online Exam Mastering System 1.0. Affected by this vulnerability is an unknown functionality of the file /sign.php?q=account.php. The manipulation of the argument name/gender/college leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2024-12930 | 1 Code-projects | 1 Simple Admin Panel | 2025-04-03 | 4.0 MEDIUM | 3.5 LOW |
|
A vulnerability was found in code-projects Simple Admin Panel 1.0 and classified as problematic. This issue affects some unknown processing of the file addCatController.php. The manipulation of the argument c_name leads to cross site scripting. The attack may be initiated remotely.
|
|||||
| CVE-2024-12932 | 1 Code-projects | 1 Simple Admin Panel | 2025-04-03 | 4.0 MEDIUM | 3.5 LOW |
|
A vulnerability was found in code-projects Simple Admin Panel 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file addSizeController.php. The manipulation of the argument size leads to cross site scripting. The attack can be launched remotely.
|
|||||
| CVE-2024-12933 | 1 Code-projects | 1 Simple Admin Panel | 2025-04-03 | 4.0 MEDIUM | 3.5 LOW |
|
A vulnerability was found in code-projects Simple Admin Panel 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file updateItemController.php. The manipulation of the argument p_name/p_desc leads to cross site scripting. The attack may be launched remotely.
|
|||||
| CVE-2024-55060 | 1 Rafed-system | 1 Rafed Cms Website | 2025-04-03 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
|||||
| CVE-2024-13019 | 1 Code-projects | 1 Chat System | 2025-04-03 | 4.0 MEDIUM | 3.5 LOW |
|
A vulnerability classified as problematic has been found in code-projects Chat System 1.0. Affected is an unknown function of the file /admin/update_room.php of the component Chat Room Page. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely.
|
|||||
| CVE-2023-22910 | 1 Mediawiki | 1 Mediawiki | 2025-04-03 | N/A | 5.4 MEDIUM |
|
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. There is XSS in Wikibase date formatting via wikibase-time-precision-* fields. This allows JavaScript execution by staff/admin users who do not intentionally have the editsitejs capability.
|
|||||
| CVE-2022-45558 | 2 Apple, Left Project | 2 Macos, Left | 2025-04-03 | N/A | 6.1 MEDIUM |
|
Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary code via the meta tag.
|
|||||
| CVE-2022-45557 | 2 Apple, Left Project | 2 Macos, Left | 2025-04-03 | N/A | 6.1 MEDIUM |
|
Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary code via file names.
|
|||||
| CVE-2022-45542 | 1 Eyoucms | 1 Eyoucms | 2025-04-03 | N/A | 5.4 MEDIUM |
|
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the FileManager component in GET parameter "filename" when editing any file.
|
|||||
| CVE-2022-45541 | 1 Eyoucms | 1 Eyoucms | 2025-04-03 | N/A | 6.1 MEDIUM |
|
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article attribute editor component in POST value "value" if the value contains a non-integer char.
|
|||||
| CVE-2022-45540 | 1 Eyoucms | 1 Eyoucms | 2025-04-03 | N/A | 6.1 MEDIUM |
|
EyouCMS <= 1.6.0 was discovered a reflected-XSS in article type editor component in POST value "name" if the value contains a malformed UTF-8 char.
|
|||||
| CVE-2022-45539 | 1 Eyoucms | 1 Eyoucms | 2025-04-03 | N/A | 6.1 MEDIUM |
|
EyouCMS <= 1.6.0 was discovered a reflected-XSS in FileManager component in GET value "activepath" when creating a new file.
|
|||||
| CVE-2022-45538 | 1 Eyoucms | 1 Eyoucms | 2025-04-03 | N/A | 6.1 MEDIUM |
|
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_GOBACK_URL".
|
|||||
| CVE-2022-45537 | 1 Eyoucms | 1 Eyoucms | 2025-04-03 | N/A | 6.1 MEDIUM |
|
EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_LIST_URL".
|
|||||
| CVE-2024-32327 | 1 Totolink | 2 N300rt, N300rt Firmware | 2025-04-03 | N/A | 5.5 MEDIUM |
|
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under the Firewall Page.
|
|||||
| CVE-2024-32332 | 1 Totolink | 2 N300rt, N300rt Firmware | 2025-04-03 | N/A | 6.1 MEDIUM |
|
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in WDS Settings under the Wireless Page.
|
|||||
| CVE-2024-32333 | 1 Totolink | 2 N300rt, N300rt Firmware | 2025-04-03 | N/A | 4.3 MEDIUM |
|
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.
|
|||||
| CVE-2024-32334 | 1 Totolink | 2 N300rt, N300rt Firmware | 2025-04-03 | N/A | 6.5 MEDIUM |
|
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering under the Firewall Page.
|
|||||
| CVE-2024-32335 | 1 Totolink | 2 N300rt, N300rt Firmware | 2025-04-03 | N/A | 5.4 MEDIUM |
|
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under the Wireless Page.
|
|||||
| CVE-2024-31065 | 1 Munyweki | 1 Insurance Management System | 2025-04-03 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the City input field.
|
|||||
| CVE-2024-31064 | 1 Munyweki | 1 Insurance Management System | 2025-04-03 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field.
|
|||||
| CVE-2024-31063 | 1 Munyweki | 1 Insurance Management System | 2025-04-03 | N/A | 6.4 MEDIUM |
|
Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Email input field.
|
|||||
| CVE-2023-23024 | 1 Book Store Management System Project | 1 Book Store Management System | 2025-04-03 | N/A | 6.1 MEDIUM |
|
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the writer parameter.
|
|||||