Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-15201 | 1 Sohu | 1 Cachecloud | 2026-01-06 | 4.0 MEDIUM | 3.5 LOW |
|
A flaw has been found in SohuTV CacheCloud up to 3.2.0. The impacted element is the function redirectNoPower of the file src/main/java/com/sohu/cache/web/controller/WebResourceController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
|
|||||
| CVE-2025-15202 | 1 Sohu | 1 Cachecloud | 2026-01-06 | 3.3 LOW | 2.4 LOW |
|
A vulnerability has been found in SohuTV CacheCloud up to 3.2.0. This affects the function taskQueueList of the file src/main/java/com/sohu/cache/web/controller/TaskController.java. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
|
|||||
| CVE-2025-15203 | 1 Sohu | 1 Cachecloud | 2026-01-06 | 3.3 LOW | 2.4 LOW |
|
A vulnerability was found in SohuTV CacheCloud up to 3.2.0. This impacts the function index of the file src/main/java/com/sohu/cache/web/controller/ResourceController.java. Performing manipulation results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
|
|||||
| CVE-2025-15204 | 1 Sohu | 1 Cachecloud | 2026-01-06 | 3.3 LOW | 2.4 LOW |
|
A vulnerability was determined in SohuTV CacheCloud up to 3.2.0. Affected is the function doQuartzList of the file src/main/java/com/sohu/cache/web/controller/QuartzManageController.java. Executing manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
|
|||||
| CVE-2025-15219 | 1 Sohu | 1 Cachecloud | 2026-01-06 | 4.0 MEDIUM | 3.5 LOW |
|
A security vulnerability has been detected in SohuTV CacheCloud up to 3.2.0. Affected by this issue is the function doMachineList/doPodList of the file src/main/java/com/sohu/cache/web/controller/MachineManageController.java. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
|
|||||
| CVE-2025-15220 | 1 Sohu | 1 Cachecloud | 2026-01-06 | 5.0 MEDIUM | 4.3 MEDIUM |
|
A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. This affects the function init of the file src/main/java/com/sohu/cache/web/controller/LoginController.java. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
|
|||||
| CVE-2025-15221 | 1 Sohu | 1 Cachecloud | 2026-01-06 | 4.0 MEDIUM | 3.5 LOW |
|
A flaw has been found in SohuTV CacheCloud up to 3.2.0. This vulnerability affects the function index of the file src/main/java/com/sohu/cache/web/controller/AppDataMigrateController.java. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
|
|||||
| CVE-2025-63947 | 1 Craigtaub | 1 Phpmsadmin | 2026-01-06 | N/A | 5.4 MEDIUM |
|
A Reflected Cross-Site Scripting (XSS) vulnerability exists in phpMsAdmin version 2.2 in the database_mode.php file. An attacker can execute arbitrary web script or HTML via the dbname parameter after a user is authenticated.
|
|||||
| CVE-2023-49269 | 1 Jayesh | 1 Hotel Management System | 2026-01-06 | N/A | 5.4 MEDIUM |
|
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'adults' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
|
|||||
| CVE-2025-40891 | 1 Nozominetworks | 2 Cmc, Guardian | 2026-01-06 | N/A | 4.7 MEDIUM |
|
A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets at two different times to inject HTML tags into asset attributes across two snapshots. Exploitation requires a victim to use the Time Machine Snapshot Diff feature on those specific snapshots and perform specific GUI actions, at which point the injected HTML renders in their ...
Show More |
|||||
| CVE-2025-40892 | 1 Nozominetworks | 2 Cmc, Guardian | 2026-01-06 | N/A | 8.9 HIGH |
|
A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing a JavaScript payload, or a victim can be socially engineered to import a malicious report template. When the victim views or imports the report, the XSS executes in their browser context, allowing the attacker to perform unauthorized actions as the victim, such as modify appl ...
Show More |
|||||
| CVE-2025-40893 | 1 Nozominetworks | 2 Cmc, Guardian | 2026-01-06 | N/A | 6.1 MEDIUM |
|
A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject HTML tags into asset attributes. When a victim views the affected assets in the Asset List (and similar functions), the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevente ...
Show More |
|||||
| CVE-2023-49270 | 1 Jayesh | 1 Hotel Management System | 2026-01-06 | N/A | 5.4 MEDIUM |
|
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_in_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
|
|||||
| CVE-2023-49271 | 1 Jayesh | 1 Hotel Management System | 2026-01-06 | N/A | 5.4 MEDIUM |
|
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_out_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.
|
|||||
| CVE-2025-67703 | 3 Esri, Linux, Microsoft | 3 Arcgis Server, Linux Kernel, Windows | 2026-01-06 | N/A | 6.1 MEDIUM |
|
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
|
|||||
| CVE-2025-67704 | 3 Esri, Linux, Microsoft | 3 Arcgis Server, Linux Kernel, Windows | 2026-01-06 | N/A | 6.1 MEDIUM |
|
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
|
|||||
| CVE-2025-67705 | 3 Esri, Linux, Microsoft | 3 Arcgis Server, Linux Kernel, Windows | 2026-01-06 | N/A | 6.1 MEDIUM |
|
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
|
|||||
| CVE-2025-67708 | 3 Esri, Linux, Microsoft | 3 Arcgis Server, Linux Kernel, Windows | 2026-01-06 | N/A | 6.1 MEDIUM |
|
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
|
|||||
| CVE-2025-67709 | 3 Esri, Linux, Microsoft | 3 Arcgis Server, Linux Kernel, Windows | 2026-01-06 | N/A | 6.1 MEDIUM |
|
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
|
|||||
| CVE-2025-67710 | 3 Esri, Linux, Microsoft | 3 Arcgis Server, Linux Kernel, Windows | 2026-01-06 | N/A | 6.1 MEDIUM |
|
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
|
|||||
| CVE-2025-67711 | 3 Esri, Linux, Microsoft | 3 Arcgis Server, Linux Kernel, Windows | 2026-01-06 | N/A | 6.1 MEDIUM |
|
There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a remote unauthenticated attacker to store files that contain malicious code that may execute in the context of a victim’s browser.
|
|||||
| CVE-2025-14519 | 1 Baowzh | 1 Hfly | 2026-01-06 | 4.0 MEDIUM | 3.5 LOW |
|
A security flaw has been discovered in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. This issue affects some unknown processing of the file /admin/index.php/advtext/add of the component advtext Module. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit has been released to the public and may be exploited. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is ...
Show More |
|||||
| CVE-2025-62857 | 1 Qnap | 1 Qumagie | 2026-01-05 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following version:
QuMagie 2.8.1 and later
|
|||||
| CVE-2025-68928 | 1 Frappe | 1 Frappe Crm | 2026-01-05 | N/A | 5.4 MEDIUM |
|
Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could set crafted URLs in a website field, which were not sanitized, causing cross-site scripting. Version 1.56.2 fixes the issue. No known workarounds are available.
|
|||||
| CVE-2024-35239 | 1 Umbraco | 1 Umbraco Forms | 2026-01-05 | N/A | 2.7 LOW |
|
Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe code into Forms components. This issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to one of the patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).
|
|||||
| CVE-2025-66845 | 1 Nooncarlett | 1 Techstore | 2026-01-05 | N/A | 6.1 MEDIUM |
|
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in TechStore version 1.0. The user_name endpoint reflects the id query parameter directly into the HTML response without output encoding or sanitization, allowing execution of arbitrary JavaScript code in a victim’s browser.
|
|||||
| CVE-2025-65270 | 1 Clincapture | 1 Captivate Electronic Data Capture | 2026-01-05 | N/A | 6.1 MEDIUM |
|
Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote attacker to execute JavaScript code in the context of the victim's browser.
|
|||||
| CVE-2024-35321 | 1 Airc | 1 Mynet | 2026-01-05 | N/A | 4.3 MEDIUM |
|
MyNET up to v26.08 was discovered to contain a Reflected cross-site scripting (XSS) vulnerability via the msgtipo parameter.
|
|||||
| CVE-2025-65790 | 1 Realtimelogic | 1 Fuguhub | 2026-01-05 | N/A | 6.1 MEDIUM |
|
A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file manager interface. FuguHub does not sanitize or restrict script execution inside SVG content. When a victim opens a crafted SVG containing an inline <script> element, the browser executes the attacker-controlled JavaScript.
|
|||||
| CVE-2025-65837 | 1 Publiccms | 1 Publiccms | 2026-01-05 | N/A | 5.4 MEDIUM |
|
PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module.
|
|||||
| CVE-2025-9550 | 1 Facets Project | 1 Facets | 2026-01-05 | N/A | 6.1 MEDIUM |
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allows Cross-Site Scripting (XSS).This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before 3.0.1.
|
|||||
| CVE-2024-20534 | 1 Cisco | 46 Desk Phone 9841, Desk Phone 9841 With Multiplatform Firmware, Desk Phone 9851 and 43 more | 2026-01-05 | N/A | 4.8 MEDIUM |
|
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users.
This vulnerability exists because the web UI of an affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the ...
Show More |
|||||
| CVE-2024-20533 | 1 Cisco | 46 Desk Phone 9841, Desk Phone 9841 With Multiplatform Firmware, Desk Phone 9851 and 43 more | 2026-01-05 | N/A | 4.8 MEDIUM |
|
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 with Cisco Multiplatform Firmware could allow an authenticated, remote attacker to conduct stored cross-site scripting (XSS) attacks against users.
This vulnerability exists because the web UI of an affected device does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the ...
Show More |
|||||
| CVE-2025-65233 | 1 Slims Project | 1 Slims | 2026-01-05 | N/A | 6.1 MEDIUM |
|
Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF' ] in index.php/sysconfig.inc.php, which allows remote attackers to execute arbitrary JavaScript in a victim's browser by supplying a crafted URL path.
|
|||||
| CVE-2021-47738 | 1 Cszcms | 1 Csz Cms | 2026-01-05 | N/A | 5.4 MEDIUM |
|
CSZ CMS 1.2.7 contains a persistent cross-site scripting vulnerability that allows unauthorized users to embed malicious JavaScript in private messages. Attackers can send messages with script payloads in the user-agent header, which will execute when an admin views the message in the backend dashboard.
|
|||||
| CVE-2021-47732 | 1 Cmsimple | 1 Cmsimple | 2026-01-05 | N/A | 6.1 MEDIUM |
|
CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows attackers to inject malicious JavaScript. Attackers can place unfiltered JavaScript code that executes when users click on Page or Files tabs, enabling persistent script injection.
|
|||||
| CVE-2024-6797 | 1 Dyadyalesha | 1 Dl Robots.txt | 2026-01-02 | N/A | 4.8 MEDIUM |
|
The DL Robots.txt WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
|
|||||
| CVE-2025-65237 | 1 Opencode | 1 Ussd Gateway | 2026-01-02 | N/A | 6.1 MEDIUM |
|
A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to execute arbitrary JavaScript in the context of a user's browser via injecting a crafted payload.
|
|||||
| CVE-2025-35034 | 1 Mieweb | 1 Enterprise Health | 2026-01-02 | N/A | 4.3 MEDIUM |
|
Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can craft a URL that can execute arbitrary JavaScript in the victim's browser. This issue is fixed as of 2025-03-14.
|
|||||
| CVE-2025-68935 | 1 Onlyoffice | 1 Document Server | 2026-01-02 | N/A | 6.4 MEDIUM |
|
ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.
|
|||||