Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-68936 | 1 Onlyoffice | 1 Document Server | 2026-01-02 | N/A | 6.4 MEDIUM |
|
ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.
|
|||||
| CVE-2025-68942 | 1 Gitea | 1 Gitea | 2026-01-02 | N/A | 5.4 MEDIUM |
|
Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.
|
|||||
| CVE-2025-66580 | 1 Openagentplatform | 1 Dive | 2026-01-02 | N/A | 9.6 CRITICAL |
|
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. A critical Stored Cross-Site Scripting (XSS) vulnerability exists in versions prior to 0.11.1 in the Mermaid diagram rendering component. The application allows the execution of arbitrary JavaScript via `javascript:`. An attacker can exploit this to inject a malicious Model Context Protocol (MCP) server configuration, leading to Remote Code Execution (RCE) on the victim's machine when the nod ...
Show More |
|||||
| CVE-2025-67634 | 1 Cisa | 1 Software Acquisition Guide | 2026-01-02 | N/A | 4.4 MEDIUM |
|
The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable to cross-site scripting via text fields. If an attacker could convince a user to import a specially-crafted JSON file, the Tool would load JavaScript from the file into the page. The JavaScript would execute in the context of the user's browser when the user submits the page (clicks 'Next').
|
|||||
| CVE-2025-68614 | 1 Librenms | 1 Librenms | 2026-01-02 | N/A | 4.3 MEDIUM |
|
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule API is vulnerable to stored cross-site scripting. Alert rules can be created or updated via LibreNMS API. The alert rule name is not properly sanitized, and can be used to inject HTML code. This issue has been patched in version 25.12.0.
|
|||||
| CVE-2025-68915 | 1 Riello-ups | 1 Netman 208 | 2026-01-02 | N/A | 5.5 MEDIUM |
|
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner.
|
|||||
| CVE-2025-67289 | 1 Frappe | 2 Erpnext, Frappe | 2026-01-02 | N/A | 9.6 CRITICAL |
|
An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.
|
|||||
| CVE-2025-67290 | 1 Dotnetfoundation | 1 Piranha Cms | 2026-01-02 | N/A | 6.1 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Excerpt field.
|
|||||
| CVE-2025-67291 | 1 Dotnetfoundation | 1 Piranha Cms | 2026-01-02 | N/A | 6.1 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field.
|
|||||
| CVE-2025-67443 | 1 Schlix | 1 Cms | 2026-01-02 | N/A | 6.1 MEDIUM |
|
Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the login form, incorrect login attempts in logs are triggered as XSS in the admin panel.
|
|||||
| CVE-2025-68115 | 1 Parseplatform | 1 Parse-server | 2026-01-02 | N/A | 6.1 MEDIUM |
|
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Parse Server's password reset and email verification HTML pages. The patch, available in versions 8.6.1 and 9.1.0-alpha.3, escapes user controlled values that are inserted into the HTML pages. No known workarounds are available.
|
|||||
| CVE-2025-68116 | 1 Filerise | 1 Filerise | 2026-01-02 | N/A | 8.9 HIGH |
|
FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site Scripting (XSS) due to unsafe handling of browser-renderable user uploads when served through the sharing and download endpoints. An attacker who can get a crafted SVG (primary) or HTML (secondary) file stored in a FileRise instance can cause JavaScript execution when a victim opens a generated share link (and in some cases via the direct download endpoint). This impacts share ...
Show More |
|||||
| CVE-2025-67787 | 1 Drivelock | 1 Drivelock | 2026-01-02 | N/A | 9.6 CRITICAL |
|
An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a network.
|
|||||
| CVE-2019-17667 | 1 Comtech | 2 H8 Heights Remote Gateway, H8 Heights Remote Gateway Firmware | 2026-01-02 | 3.5 LOW | 5.4 MEDIUM |
|
Comtech H8 Heights Remote Gateway 2.5.1 devices allow XSS and HTML injection via the Site Name (aka SiteName) field.
|
|||||
| CVE-2025-51962 | 1 Microstudio | 1 Microstudio | 2026-01-02 | N/A | 6.1 MEDIUM |
|
A HTML Injection vulnerability in the comment section of the project page in MicroStudio 24.01.29 allows remote attackers to inject arbitrary web script or HTML via the text parameter of add_project_comment function.
|
|||||
| CVE-2025-68927 | 1 Libredesk | 1 Libredesk | 2026-01-02 | N/A | 6.1 MEDIUM |
|
Libredesk is a self-hosted customer support desk. Prior to version 0.8.6-beta, LibreDesk is vulnerable to stored HTML injection in the contact notes feature. When adding notes via POST /api/v1/contacts/{id}/notes, the backend automatically wraps user input in <p> tags. However, by intercepting the request and removing the <p> tag, an attacker can inject arbitrary HTML elements such as forms and images, which are then stored and rendered without proper sanitization. This can lead to phishing, CSR ...
Show More |
|||||
| CVE-2024-25814 | 1 Airc | 1 Mynet | 2026-01-02 | N/A | 6.1 MEDIUM |
|
MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the msg parameter.
|
|||||
| CVE-2024-25812 | 1 Airc | 1 Mynet | 2026-01-02 | N/A | 6.1 MEDIUM |
|
MyNET up to v26.05 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the src parameter.
|
|||||
| CVE-2023-36337 | 1 Inventory Management System Project | 1 Inventory Management System | 2026-01-02 | N/A | 6.1 MEDIUM |
|
A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP Inventory Management System 1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
|||||
| CVE-2025-68946 | 1 Gitea | 1 Gitea | 2025-12-31 | N/A | 5.4 MEDIUM |
|
In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.
|
|||||
| CVE-2021-47733 | 1 Cmsimple | 1 Cmsimple | 2025-12-31 | N/A | 6.1 MEDIUM |
|
CMSimple 5.4 contains a cross-site scripting vulnerability that allows attackers to bypass input filtering by using HTML to Unicode encoding. Attackers can inject malicious scripts by encoding payloads like ')-alert(1)// and execute arbitrary JavaScript when victims interact with delete buttons.
|
|||||
| CVE-2021-47737 | 1 Cszcms | 1 Csz Cms | 2025-12-31 | N/A | 5.4 MEDIUM |
|
CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in message titles. Attackers can craft POST requests to the member messaging system with HTML-based links to potentially conduct phishing or social engineering attacks.
|
|||||
| CVE-2025-67349 | 1 Fluentcms | 1 Fluentcms | 2025-12-31 | N/A | 6.1 MEDIUM |
|
A cross-site scripting (XSS) vulnerability was identified in FluentCMS 1.2.3. After logging in as an admin and navigating to the "Add Page" function, the application fails to properly sanitize input in the <head> section, allowing remote attackers to inject arbitrary script tags.
|
|||||
| CVE-2025-61914 | 1 N8n | 1 N8n | 2025-12-31 | N/A | 7.3 HIGH |
|
n8n is an open source workflow automation platform. Prior to version 1.114.0, a stored Cross-Site Scripting (XSS) vulnerability may occur in n8n when using the “Respond to Webhook” node. When this node responds with HTML content containing executable scripts, the payload may execute directly in the top-level window, rather than within the expected sandbox introduced in version 1.103.0. This behavior can enable a malicious actor with workflow creation permissions to execute arbitrary JavaScript i ...
Show More |
|||||
| CVE-2025-15355 | 2025-12-31 | N/A | 6.1 MEDIUM | ||
|
ISOinsight developed by NetVision Information has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
|
|||||
| CVE-2025-55064 | 2025-12-31 | N/A | 4.8 MEDIUM | ||
|
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
|
|||||
| CVE-2025-55062 | 2025-12-31 | N/A | 4.8 MEDIUM | ||
|
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
|
|||||
| CVE-2025-55063 | 2025-12-31 | N/A | 4.8 MEDIUM | ||
|
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
|
|||||
| CVE-2025-15248 | 2025-12-31 | 4.0 MEDIUM | 3.5 LOW | ||
|
A security flaw has been discovered in sunhailin12315 product-review 商品评价系统 up to 91ead6890b4065bb45b7602d0d73348e75cb4639. This affects an unknown part of the component Write a Review. Performing manipulation of the argument content results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited. This product adopts a rolling release strategy to maintain continuous delivery The project was informed of the probl ...
Show More |
|||||
| CVE-2022-50801 | 2025-12-31 | N/A | 4.3 MEDIUM | ||
|
JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to authenticated stored cross-site scripting (XSS) attacks, allowing attackers with authenticated access to inject malicious scripts that will be executed in other users' browsers when they view the affected content.
|
|||||
| CVE-2025-15249 | 2025-12-31 | 4.0 MEDIUM | 3.5 LOW | ||
|
A weakness has been identified in zhujunliang3 work_platform up to 6bc5a50bb527ce27f7906d11ea6ec139beb79c31. This vulnerability affects unknown code of the component Content Handler. Executing manipulation can lead to cross site scripting. The attack may be performed from remote. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue ...
Show More |
|||||
| CVE-2021-47725 | 2025-12-31 | N/A | 5.4 MEDIUM | ||
|
STVS ProVision 5.9.10 contains a cross-site scripting vulnerability in the 'files' POST parameter that allows authenticated attackers to inject arbitrary HTML code. Attackers can exploit the unvalidated input to execute malicious scripts within a user's browser session in the context of the affected site.
|
|||||
| CVE-2019-25262 | 2025-12-31 | 4.0 MEDIUM | 3.5 LOW | ||
|
A security vulnerability has been detected in elinicksic Razgover up to db37dfc5c82f023a40f2f7834ded6633fb2b5262. This affects an unknown part of the file Chattify/send.php of the component Chat Message Handler. Such manipulation of the argument msg leads to cross site scripting. The attack may be performed from remote. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The name of the patch ...
Show More |
|||||
| CVE-2021-47743 | 2025-12-31 | N/A | 6.1 MEDIUM | ||
|
COMMAX Biometric Access Control System 1.0.0 contains an unauthenticated reflected cross-site scripting vulnerability in cookie parameters 'CMX_ADMIN_NM' and 'CMX_COMPLEX_NM'. Attackers can inject malicious HTML and JavaScript code into these cookie values to execute arbitrary scripts in a victim's browser session.
|
|||||
| CVE-2025-57462 | 1 Machsol | 1 Machpanel | 2025-12-31 | N/A | 6.1 MEDIUM |
|
Stored cross-site scripting (xss) in machsol machpanel 8.0.32 allows attackers to execute arbitrary web scripts or HTML via a crafted PDF file.
|
|||||
| CVE-2025-65442 | 1 Xxyopen | 1 Novel | 2025-12-31 | N/A | 6.1 MEDIUM |
|
DOM-based Cross-Site Scripting (XSS) vulnerability in 201206030 novel V3.5.0 allows remote attackers to execute arbitrary JavaScript code or disclose sensitive information (e.g., user session cookies) via a crafted "wvstest" parameter in the URL or malicious script injection into window.localStorage. The vulnerability arises from insufficient validation and encoding of user-controllable data in the book comment module: unfiltered user input is stored in the backend database (book_comment table, ...
Show More |
|||||
| CVE-2025-67163 | 1 Simplemachines | 1 Simple Machines Forum | 2025-12-31 | N/A | 6.1 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Forum Name parameter.
|
|||||
| CVE-2025-44998 | 1 Prasathmani | 1 Tiny File Manager | 2025-12-31 | N/A | 6.1 MEDIUM |
|
A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.
|
|||||
| CVE-2022-40490 | 1 Prasathmani | 1 Tiny File Manager | 2025-12-31 | N/A | 4.8 MEDIUM |
|
Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing file.
|
|||||
| CVE-2021-40966 | 1 Prasathmani | 1 Tiny File Manager | 2025-12-31 | 3.5 LOW | 5.4 MEDIUM |
|
A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and javascript in its name. A malicious user can upload a file with a malicious filename containing javascript code and it will run on any user browser when they access the server.
|
|||||