Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-2888 | 1 Boldgrid | 1 Post And Page Builder | 2025-03-19 | N/A | 6.5 MEDIUM |
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.26.2.
|
|||||
| CVE-2024-34811 | 1 Veronalabs | 1 Wp Sms | 2025-03-19 | N/A | 5.9 MEDIUM |
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.5.1.
|
|||||
| CVE-2024-33928 | 1 Codebard | 1 Codebard\'s Patron Button And Widgets For Patreon | 2025-03-19 | N/A | 7.1 HIGH |
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard's Patron Button and Widgets for Patreon allows Reflected XSS.This issue affects CodeBard's Patron Button and Widgets for Patreon: from n/a through 2.2.0.
|
|||||
| CVE-2024-50656 | 1 Angeljudesuarez | 1 Placement Management System | 2025-03-19 | N/A | 6.1 MEDIUM |
|
itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.
|
|||||
| CVE-2024-44684 | 1 Tpmecms | 1 Tpmecms | 2025-03-19 | N/A | 6.1 MEDIUM |
|
TpMeCMS 1.3.3.2 is vulnerable to Cross Site Scripting (XSS) in /h.php/page?ref=addtabs via the "Title," "Images," and "Content" fields.
|
|||||
| CVE-2024-44449 | 2025-03-19 | N/A | 6.1 MEDIUM | ||
|
Cross Site Scripting vulnerability in Quorum onQ OS v.6.0.0.5.2064 allows a remote attacker to obtain sensitive information via the msg parameter in the Login page.
|
|||||
| CVE-2024-41599 | 1 Ruoyi | 1 Ruoyi | 2025-03-19 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the file upload method
|
|||||
| CVE-2024-39125 | 1 Roundup-tracker | 1 Roundup | 2025-03-19 | N/A | 5.4 MEDIUM |
|
Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.
|
|||||
| CVE-2023-43971 | 1 Lizhipay | 1 Acg-faka | 2025-03-19 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting vulnerability in ACG-faka v1.1.7 allows a remote attacker to execute arbitrary code via the encode parameter in Index.php.
|
|||||
| CVE-2022-45543 | 1 Discuz | 1 Discuzx | 2025-03-19 | N/A | 6.1 MEDIUM |
|
Cross site scripting (XSS) vulnerability in DiscuzX 3.4 allows attackers to execute arbitrary code via the datetline, title, tpp, or username parameters via the audit search.
|
|||||
| CVE-2025-22759 | 1 Boldgrid | 1 Post And Page Builder By Boldgrid - Visual Drag And Drop Editor | 2025-03-19 | N/A | 6.5 MEDIUM |
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and Page Builder by BoldGrid – Visual Drag and Drop Editor allows Stored XSS.This issue affects Post and Page Builder by BoldGrid – Visual Drag and Drop Editor: from n/a through 1.27.4.
|
|||||
| CVE-2025-22760 | 1 Codebard | 1 Codebard Help Desk | 2025-03-19 | N/A | 7.1 HIGH |
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard Help Desk allows Reflected XSS.This issue affects CodeBard Help Desk: from n/a through 1.1.2.
|
|||||
| CVE-2024-21730 | 1 Joomla | 1 Joomla\! | 2025-03-19 | N/A | 5.4 MEDIUM |
|
The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.
|
|||||
| CVE-2023-25764 | 1 Jenkins | 1 Email Extension | 2025-03-19 | N/A | 5.4 MEDIUM |
|
Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generated during template rendering, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or change custom email templates.
|
|||||
| CVE-2024-40746 | 1 Hikashop | 1 Hikashop | 2025-03-19 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload in the `description` parameter of any product. The `description `parameter is not sanitised in the backend.
|
|||||
| CVE-2023-25761 | 1 Jenkins | 1 Junit | 2025-03-19 | N/A | 5.4 MEDIUM |
|
Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control test case class names in the JUnit resources processed by the plugin.
|
|||||
| CVE-2021-23980 | 1 Mozilla | 1 Bleach | 2025-03-19 | N/A | 6.1 MEDIUM |
|
A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comments defaults to True.
|
|||||
| CVE-2019-17003 | 1 Mozilla | 1 Firefox | 2025-03-19 | N/A | 6.1 MEDIUM |
|
Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.
|
|||||
| CVE-2024-38379 | 1 Apache | 1 Allura | 2025-03-19 | N/A | 4.8 MEDIUM |
|
Apache Allura's neighborhood settings are vulnerable to a stored XSS attack. Only neighborhood admins can access these settings, so the scope of risk is limited to configurations where neighborhood admins are not fully trusted.
This issue affects Apache Allura: from 1.4.0 through 1.17.0.
Users are recommended to upgrade to version 1.17.1, which fixes the issue.
|
|||||
| CVE-2023-48985 | 1 Cusg | 1 Content Management System | 2025-03-19 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the login.php component.
|
|||||
| CVE-2022-48326 | 1 Mapos | 1 Map-os | 2025-03-19 | N/A | 6.1 MEDIUM |
|
Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parameters: (1) nome, (2) aCliente, (3) eCliente, (4) dCliente, (5) vCliente, (6) aProduto, (7) eProduto, (8) dProduto, (9) vProduto, (10) aServico, (11) eServico, (12) dServico, (13) vServico, (14) aOs, (15) eOs, (16) dOs, (17) vOs, (18) aVenda, (19) eVenda, (20) dVenda, (21) vVenda, (22) aGarantia, (23) eGarantia, (24) dGarantia, (25) vGarantia, (26) aArquivo, (2 ...
Show More |
|||||
| CVE-2022-48325 | 1 Mapos | 1 Map-os | 2025-03-19 | N/A | 6.1 MEDIUM |
|
Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parameters: (1) year, (2) oldSenha, (3) novaSenha, (4) termo, (5) nome, (6) cnpj, (7) ie, (8) cep, (9) logradouro, (10) numero, (11) bairro, (12) cidade, (13) uf, (14) telefone, (15) email, (16) id, (17) app_name, (18) per_page, (19) app_theme, (20) os_notification, (21) email_automatico, (22) control_estoque, (23) notifica_whats, (24) control_baixa, (25) control_e ...
Show More |
|||||
| CVE-2022-48324 | 1 Mapos | 1 Map-os | 2025-03-19 | N/A | 6.1 MEDIUM |
|
Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parameters: (1) pesquisa, (2) data, (3) data2, (4) nome, (5) descricao, (6) idDocumentos, (7) id in file application/controllers/Arquivos.php; (8) senha, (9) nomeCliente, (10) contato, (11) documento, (12) telefone, (13) celular, (14) email, (15) rua, (16) numero, (17) complemento, (18) bairro, (19) cidade, (20) estado, (21) cep, (22) idClientes, (23) id in file ap ...
Show More |
|||||
| CVE-2021-40555 | 1 Flatcore | 1 Flatcore | 2025-03-19 | N/A | 5.4 MEDIUM |
|
Cross site scripting (XSS) vulnerability in flatCore-CMS 2.2.15 allows attackers to execute arbitrary code via description field on the new page creation form.
|
|||||
| CVE-2023-6047 | 1 Algoritimbilisim | 1 E-commerce Software | 2025-03-19 | N/A | 6.1 MEDIUM |
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Algoritim E-commerce Software allows Reflected XSS.This issue affects E-commerce Software: before 3.9.2.
|
|||||
| CVE-2024-51122 | 2025-03-18 | N/A | 6.1 MEDIUM | ||
|
Cross Site Scripting vulnerability in Zertificon Z1 SecureMail Z1 CertServer v.3.16.4-2516-debian12 alllows a remote attacker to execute arbitrary code via the ST, L, O, OU, CN parameters.
|
|||||
| CVE-2024-4094 | 1 Sharethis | 1 Simple Share Buttons Adder | 2025-03-18 | N/A | 5.4 MEDIUM |
|
The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
|
|||||
| CVE-2024-37803 | 1 Health Care Hospital Management System Project | 1 Health Care Hospital Management System | 2025-03-18 | N/A | 5.4 MEDIUM |
|
Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname and lname parameters under the Staff Info page.
|
|||||
| CVE-2025-28870 | 1 Amocrm | 1 Amocrm | 2025-03-18 | N/A | 6.5 MEDIUM |
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in amocrm amoCRM WebForm allows DOM-Based XSS. This issue affects amoCRM WebForm: from n/a through 1.1.
|
|||||
| CVE-2024-41614 | 1 Symphony-cms | 1 Symphony Cms | 2025-03-18 | N/A | 4.8 MEDIUM |
|
symphonycms <=2.7.10 is vulnerable to Cross Site Scripting (XSS) in the Comment component for articles.
|
|||||
| CVE-2024-41572 | 1 Lang-learn-guy | 1 Learning With Texts | 2025-03-18 | N/A | 6.1 MEDIUM |
|
Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in URL parameters. Remote attackers can inject JavaScript code without authorization. Exploiting this vulnerability, attackers can steal user credentials or execute actions such as injecting malicious scripts or redirecting users to malicious sites.
|
|||||
| CVE-2024-40604 | 1 Mediawiki | 1 Mediawiki | 2025-03-18 | N/A | 4.8 MEDIUM |
|
An issue was discovered in the Nimbus skin for MediaWiki through 1.42.1. There is Stored XSS via MediaWiki:Nimbus-sidebar menu and submenu entries.
|
|||||
| CVE-2024-39241 | 1 Skycaiji | 1 Skycaiji | 2025-03-18 | N/A | 6.1 MEDIUM |
|
Cross Site Scripting (XSS) vulnerability in skycaiji 2.8 allows attackers to run arbitrary code via /admin/tool/preview.
|
|||||
| CVE-2022-48327 | 1 Mapos | 1 Map-os | 2025-03-18 | N/A | 6.1 MEDIUM |
|
Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parameters: (1) dataInicial, (2) dataFinal, (3) tipocliente, (4) format, (5) precoInicial, (6) precoFinal, (7) estoqueInicial, (8) estoqueFinal, (9) de_id, (10) ate_id, (11) clientes_id, (12) origem, (13) cliente, (14) responsavel, (15) status, (16) tipo, (17) situacao in file application/controllers/Relatorios.php; (18) preco, (19) nome, (20) descricao, (21) idSer ...
Show More |
|||||
| CVE-2024-26311 | 1 Archerirm | 1 Archer | 2025-03-18 | N/A | 5.7 MEDIUM |
|
Archer Platform 6.x before 6.14 P2 HF1 (6.14.0.2.1) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application. This code is then reflected to the victim and gets executed by the web browser in the context of the vulnerable web application.
|
|||||
| CVE-2024-34090 | 1 Archerirm | 1 Archer | 2025-03-18 | N/A | 7.3 HIGH |
|
An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. The login banner in the Archer Control Panel (ACP) did not previously escape content appropriately. 6.14 P3 (6.14.0.3) is also a fixed release.
|
|||||
| CVE-2024-26313 | 1 Archerirm | 1 Archer | 2025-03-18 | N/A | 7.3 HIGH |
|
Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application. 6.13.P3 HF1 (6.13.0.3.1) is also a fixed release.
|
|||||
| CVE-2024-41707 | 1 Archerirm | 1 Archer | 2025-03-18 | N/A | 4.8 MEDIUM |
|
An issue was discovered in Archer Platform 6 before 2024.06. Authenticated users can achieve HTML content injection. A remote authenticated malicious Archer user could potentially exploit this to store malicious HTML code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable application.
|
|||||
| CVE-2024-41587 | 1 Draytek | 48 Vigor1000b, Vigor1000b Firmware, Vigor165 and 45 more | 2025-03-18 | N/A | 5.4 MEDIUM |
|
Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6.
|
|||||
| CVE-2024-36359 | 1 Trendmicro | 1 Interscan Web Security Virtual Appliance | 2025-03-18 | N/A | 5.4 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 could allow an attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
|
|||||