Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-25234 | 2025-12-29 | N/A | 5.3 MEDIUM | ||
|
SmartHouse Webapp 6.5.33 contains multiple cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform unauthorized actions. Attackers can exploit these vulnerabilities by tricking logged-in users into visiting malicious websites or injecting malicious scripts into various application parameters.
|
|||||
| CVE-2025-2154 | 2025-12-29 | N/A | 5.4 MEDIUM | ||
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Stored XSS.This issue affects Specto CM: before 17032025.
|
|||||
| CVE-2025-15095 | 2025-12-29 | 4.0 MEDIUM | 3.5 LOW | ||
|
A security vulnerability has been detected in postmanlabs httpbin up to 0.6.1. This affects an unknown function of the file httpbin-master/httpbin/core.py. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
|
|||||
| CVE-2025-15149 | 2025-12-29 | 3.3 LOW | 2.4 LOW | ||
|
A vulnerability has been found in rawchen ecms up to b59d7feaa9094234e8aa6c8c6b290621ca575ded. Affected by this vulnerability is the function updateProductServlet of the file src/servlet/product/updateProductServlet.java of the component Add New Product Page. The manipulation of the argument productName leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. This product follows a rolling release approach for con ...
Show More |
|||||
| CVE-2025-2406 | 2025-12-29 | N/A | 7.6 HIGH | ||
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Trizbi allows Cross-Site Scripting (XSS).This issue affects Trizbi: before 2.144.4.
|
|||||
| CVE-2025-15134 | 2025-12-29 | 4.0 MEDIUM | 3.5 LOW | ||
|
A security flaw has been discovered in yourmaileyes MOOC up to 1.17. This affects the function subreview of the file mooc/controller/MainController.java of the component Submission Handler. Performing manipulation of the argument review results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. The project was informed of the problem early through an issue report but has not responded yet.
|
|||||
| CVE-2025-2307 | 2025-12-29 | N/A | 7.6 HIGH | ||
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Aidango allows Cross-Site Scripting (XSS).This issue affects Aidango: before 2.144.4.
|
|||||
| CVE-2025-2405 | 2025-12-29 | N/A | 7.6 HIGH | ||
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Verisay Communication and Information Technology Industry and Trade Ltd. Co. Titarus allows Cross-Site Scripting (XSS).This issue affects Titarus: before 2.144.4.
|
|||||
| CVE-2025-64030 | 1 Chinasystems | 1 Eximbills Enterprise | 2025-12-29 | N/A | 5.4 MEDIUM |
|
Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via the /EximBillWeb/servlets/WSTrxManager endpoint. Unsanitized user input in the TMPL_INFO parameter is stored server-side and rendered to other users, enabling arbitrary JavaScript execution in their browsers.
|
|||||
| CVE-2023-53976 | 1 Mybb | 1 Mybb | 2025-12-27 | N/A | 5.4 MEDIUM |
|
myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the template management system that allows authenticated administrators to inject malicious scripts when creating new templates. Attackers can exploit this vulnerability by inserting script payloads in the template title field when adding new templates through the 'Templates and Style' > 'Templates' > 'Manage Templates' > 'Global Templates' interface, causing arbitrary JavaScript to execute when the template is viewed.
|
|||||
| CVE-2025-2748 | 1 Kentico | 1 Xperience | 2025-12-27 | N/A | 6.1 MEDIUM |
|
The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico Xperience through 13.0.178.
|
|||||
| CVE-2024-58323 | 1 Kentico | 1 Xperience | 2025-12-27 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Checkbox form component. This allows malicious scripts to execute in users' browsers by exploiting HTML support in the form builder.
|
|||||
| CVE-2024-58322 | 1 Kentico | 1 Xperience | 2025-12-27 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping options configuration. This could lead to potential theft of sensitive data by executing malicious scripts in users' browsers.
|
|||||
| CVE-2024-58321 | 1 Kentico | 1 Xperience | 2025-12-27 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form validation rule configuration. Attackers can exploit this vulnerability to execute malicious scripts that will run in users' browsers.
|
|||||
| CVE-2024-58319 | 1 Kentico | 1 Xperience | 2025-12-27 | N/A | 6.1 MEDIUM |
|
A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Pages dashboard widget configuration dialog. Attackers can exploit this vulnerability to execute malicious scripts in administrative users' browsers.
|
|||||
| CVE-2024-58318 | 1 Kentico | 1 Xperience | 2025-12-27 | N/A | 6.1 MEDIUM |
|
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the rich text editor component for page and form builders. Attackers can exploit this vulnerability by entering malicious URIs, potentially allowing malicious scripts to execute in users' browsers.
|
|||||
| CVE-2023-53978 | 1 Mybb | 1 Mybb | 2025-12-27 | N/A | 5.4 MEDIUM |
|
myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum announcement system that allows authenticated administrators to inject malicious scripts when creating announcements. Attackers can exploit this vulnerability by inserting script payloads in the announcement title field when adding announcements through the 'Forums and Posts' > 'Forum Announcements' interface, causing arbitrary JavaScript to execute when the announcement is displayed on the forum.
|
|||||
| CVE-2023-53977 | 1 Mybb | 1 Mybb | 2025-12-27 | N/A | 5.4 MEDIUM |
|
myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum management system that allows authenticated administrators to inject malicious scripts when creating new forums. Attackers can exploit this vulnerability by inserting script payloads in the forum title field when adding new forums through the 'Forums and Posts' > 'Forum Management' interface, causing arbitrary JavaScript to execute when the forum listing is viewed.
|
|||||
| CVE-2023-53953 | 1 Websitebaker | 1 Websitebaker | 2025-12-27 | N/A | 5.4 MEDIUM |
|
WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts when creating web pages. Attackers can craft malicious payloads in page titles that execute arbitrary JavaScript when the page is viewed by other users.
|
|||||
| CVE-2023-53932 | 1 S9y | 1 Serendipity | 2025-12-27 | N/A | 5.4 MEDIUM |
|
Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry creation. Attackers can craft entries with JavaScript payloads that will execute when other users view the compromised blog post.
|
|||||
| CVE-2023-53931 | 1 Revive-adserver | 1 Revive Adserver | 2025-12-27 | N/A | 6.1 MEDIUM |
|
Revive Adserver 5.4.1 contains a cross-site scripting vulnerability in the banner advanced configuration page that allows attackers to inject malicious scripts. Attackers can craft a malicious link to the banner-advanced.php endpoint with XSS payloads in prepend and append parameters to execute arbitrary JavaScript when an admin views the page.
|
|||||
| CVE-2023-53927 | 1 Phpjabbers | 1 Simple Cms | 2025-12-27 | N/A | 5.4 MEDIUM |
|
PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through section name parameters. Attackers can create sections with embedded JavaScript payloads that will execute when administrators view the sections, potentially enabling client-side code execution.
|
|||||
| CVE-2023-53925 | 1 Ulicms | 1 Ulicms | 2025-12-27 | N/A | 6.1 MEDIUM |
|
UliCMS 2023.1 contains a stored cross-site scripting vulnerability that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the file management interface that execute arbitrary scripts when viewed by other users.
|
|||||
| CVE-2023-53920 | 1 Podcastgenerator | 1 Podcast Generator | 2025-12-27 | N/A | 5.4 MEDIUM |
|
PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the podcast title field accessible through the podcast details interface (podcast_details.php). Malicious JavaScript payloads injected into the podcast title execute when users visit the application's home page.
|
|||||
| CVE-2023-53919 | 1 Podcastgenerator | 1 Podcast Generator | 2025-12-27 | N/A | 5.4 MEDIUM |
|
PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the Freebox content field accessible through the theme customization interface (theme_freebox.php). Malicious JavaScript payloads injected into the Freebox content execute when users visit the application's home page.
|
|||||
| CVE-2023-53918 | 1 Podcastgenerator | 1 Podcast Generator | 2025-12-27 | N/A | 6.1 MEDIUM |
|
PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the episode title field accessible through the episodes upload interface (episodes_upload.php). Malicious JavaScript payloads injected into episode titles execute when administrators view the episodes list page (episodes_list.php).
|
|||||
| CVE-2023-53916 | 1 Zenphoto | 1 Zenphoto | 2025-12-27 | N/A | 4.6 MEDIUM |
|
Zenphoto 1.6 contains a stored cross-site scripting vulnerability in the user postal code field accessible through the admin-users.php interface. When administrators view user information imported as HTML, malicious JavaScript payloads injected into the postal code field execute in their browser context.
|
|||||
| CVE-2023-53915 | 1 Zenphoto | 1 Zenphoto | 2025-12-27 | N/A | 4.6 MEDIUM |
|
Zenphoto 1.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting HTML content into album descriptions. Attackers can create albums with malicious iframe or script tags in the description field that execute when users view the album page.
|
|||||
| CVE-2023-53911 | 1 Textpattern | 1 Textpattern | 2025-12-27 | N/A | 5.4 MEDIUM |
|
Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert JavaScript payloads into the excerpt, which will execute when the article is viewed by other users.
|
|||||
| CVE-2023-53910 | 1 Wbce | 1 Wbce Cms | 2025-12-27 | N/A | 5.4 MEDIUM |
|
WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by inserting script tags into page content through the WYSIWYG editor. Attackers can submit POST requests to /wbce/modules/wysiwyg/save.php with malicious script content in the content parameter to execute JavaScript when users view the affected page.
|
|||||
| CVE-2023-53909 | 1 Wbce | 1 Wbce Cms | 2025-12-27 | N/A | 5.4 MEDIUM |
|
WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by uploading crafted SVG files through the media manager. Attackers can upload SVG files containing script tags to the /wbce/modules/elfinder/ef/php/connector.wbce.php endpoint and execute JavaScript when victims access the uploaded file.
|
|||||
| CVE-2023-53906 | 1 Projectsend | 1 Projectsend | 2025-12-27 | N/A | 4.8 MEDIUM |
|
projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets section that will execute when other users load the affected page, enabling persistent script injection.
|
|||||
| CVE-2023-53898 | 1 Rukovoditel | 1 Rukovoditel | 2025-12-27 | N/A | 5.4 MEDIUM |
|
Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert iframe and script payloads in application copyright text to execute arbitrary JavaScript in victim browsers.
|
|||||
| CVE-2023-53897 | 1 Rukovoditel | 1 Rukovoditel | 2025-12-27 | N/A | 5.4 MEDIUM |
|
Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts. Attackers can insert XSS payloads in project task comments to execute arbitrary JavaScript in victim browsers.
|
|||||
| CVE-2023-53738 | 1 Kentico | 1 Xperience | 2025-12-27 | N/A | 5.4 MEDIUM |
|
A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via page preview URLs. Attackers can exploit this vulnerability to execute arbitrary scripts in users' browsers during page preview interactions.
|
|||||
| CVE-2023-53737 | 1 Kentico | 1 Xperience | 2025-12-27 | N/A | 4.8 MEDIUM |
|
A stored cross-site scripting vulnerability in Kentico Xperience allows global administrators to inject malicious payloads via the Localization application. Attackers can execute scripts that could affect multiple parts of the administration interface.
|
|||||
| CVE-2023-53736 | 1 Kentico | 1 Xperience | 2025-12-27 | N/A | 5.4 MEDIUM |
|
A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts in the administration interface. Attackers can exploit this vulnerability to execute arbitrary scripts within the administrative context.
|
|||||
| CVE-2022-50685 | 1 Kentico | 1 Xperience | 2025-12-27 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via XML file uploads as page attachments or metafiles. Attackers can upload malicious XML files that enable stored XSS, allowing malicious scripts to execute in users' browsers.
|
|||||
| CVE-2022-50684 | 1 Kentico | 1 Xperience | 2025-12-27 | N/A | 6.1 MEDIUM |
|
An HTML injection vulnerability in Kentico Xperience allows attackers to inject malicious HTML values into form submission emails via unencoded form fields. Unencoded form values could enable HTML content execution in recipient email clients, potentially compromising email security.
|
|||||
| CVE-2022-50683 | 1 Kentico | 1 Xperience | 2025-12-27 | N/A | 5.4 MEDIUM |
|
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form redirect URL configuration. This allows malicious scripts to execute in users' browsers through unvalidated form configuration settings.
|
|||||