Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-11496 | 2025-12-23 | N/A | 6.1 MEDIUM | ||
|
The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
|
|||||
| CVE-2025-14298 | 2025-12-23 | N/A | 5.4 MEDIUM | ||
|
The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `thegem_te_search` shortcode in all versions up to, and including, 1.32.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerabil ...
Show More |
|||||
| CVE-2025-9343 | 2025-12-23 | N/A | 7.2 HIGH | ||
|
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket subjects in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
|
|||||
| CVE-2025-14635 | 2025-12-23 | N/A | 6.4 MEDIUM | ||
|
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_page_custom_js' parameter in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, despite the intended role restriction of Custom JS to Administrat ...
Show More |
|||||
| CVE-2025-66918 | 1 Hashenudara | 1 Edoc-doctor-appointment-system | 2025-12-23 | N/A | 8.8 HIGH |
|
edoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter.
|
|||||
| CVE-2025-65187 | 1 Civicrm | 1 Civicrm | 2025-12-23 | N/A | 6.1 MEDIUM |
|
A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authenticated user can inject malicious JavaScript into this field and it executes whenever the page is viewed.
|
|||||
| CVE-2025-65858 | 1 Janeczku | 1 Calibre-web | 2025-12-23 | N/A | 3.5 LOW |
|
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed.
|
|||||
| CVE-2025-14244 | 1 Njtech | 1 Greencms | 2025-12-23 | 3.3 LOW | 2.4 LOW |
|
A flaw has been found in GreenCMS 2.3.0603. Affected by this issue is some unknown functionality of the file /Admin/Controller/CustomController.class.php of the component Menu Management Page. This manipulation of the argument Link causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
|
|||||
| CVE-2020-25789 | 1 Tt-rss | 1 Tiny Tiny Rss | 2025-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
|
|||||
| CVE-2025-7969 | 1 Markdown-it Project | 1 Markdown-it | 2025-12-22 | N/A | 6.1 MEDIUM |
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/renderer.mjs.
This issue affects markdown-it: 14.1.0. NOTE: the Supplier does not consider this issue to be a vulnerability.
|
|||||
| CVE-2020-28129 | 1 Admerc | 1 Gym Management System | 2025-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Stored Cross-site scripting (XSS) vulnerability in SourceCodester Gym Management System 1.0 allows users to inject and store arbitrary JavaScript code in index.php?page=packages via vulnerable fields 'Package Name' and 'Description'.
|
|||||
| CVE-2025-67724 | 1 Tornadoweb | 1 Tornado | 2025-12-22 | N/A | 5.4 MEDIUM |
|
Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom "reason" ...
Show More |
|||||
| CVE-2025-66492 | 1 Masacms | 1 Masacms | 2025-12-22 | N/A | 8.2 HIGH |
|
Masa CMS is an open source Enterprise Content Management platform. Versions 7.2.8 and below, 7.3.1 through 7.3.13, 7.4.0-alpha.1 through 7.4.8 and 7.5.0 through 7.5.1 are vulnerable to XSS when an unsanitized value of the ajax URL query parameter is directly included within the <head> section of the HTML page. An attacker can execute arbitrary scripts in the context of the user's session, potentially leading to Session Hijacking, Data Theft, Defacement and Malware Distribution. This issue is fix ...
Show More |
|||||
| CVE-2025-52180 | 1 Zucchetti | 1 Ad Hoc Infinity | 2025-12-22 | N/A | 6.1 MEDIUM |
|
Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated attackers to inject arbitrary JavaScript via the pHtmlSource parameter of the /ahi/jsp/gsfr_feditorHTML.jsp?pHtmlSource endpoint.
|
|||||
| CVE-2025-12019 | 1 Mer.vin | 1 Featured Image | 2025-12-22 | N/A | 4.4 MEDIUM |
|
The Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image metadata in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been ...
Show More |
|||||
| CVE-2025-33116 | 1 Ibm | 1 Watson Studio | 2025-12-22 | N/A | 4.4 MEDIUM |
|
IBM Watson Studio 4.0 through 5.2.0 on Cloud Pak for Data is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
|
|||||
| CVE-2023-32531 | 1 Trendmicro | 1 Apex Central | 2025-12-22 | N/A | 6.1 MEDIUM |
|
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers.
This is similar to, but not identical to CVE-2023-32532 through 32535.
|
|||||
| CVE-2023-32535 | 1 Trendmicro | 1 Apex Central | 2025-12-22 | N/A | 6.1 MEDIUM |
|
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers.
This is similar to, but not identical to CVE-2023-32531 through 32534.
|
|||||
| CVE-2023-52328 | 1 Trendmicro | 1 Apex Central | 2025-12-22 | N/A | 6.1 MEDIUM |
|
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers.
Please note this vulnerability is similar, but not identical to CVE-2023-52329.
|
|||||
| CVE-2023-52329 | 1 Trendmicro | 1 Apex Central | 2025-12-22 | N/A | 6.1 MEDIUM |
|
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers.
Please note this vulnerability is similar, but not identical to CVE-2023-52326.
|
|||||
| CVE-2023-52326 | 1 Trendmicro | 1 Apex Central | 2025-12-22 | N/A | 6.1 MEDIUM |
|
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers.
Please note this vulnerability is similar, but not identical to CVE-2023-52327.
|
|||||
| CVE-2023-32533 | 1 Trendmicro | 1 Apex Central | 2025-12-22 | N/A | 6.1 MEDIUM |
|
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers.
This is similar to, but not identical to CVE-2023-32531 through 32535.
|
|||||
| CVE-2023-32537 | 1 Trendmicro | 1 Apex Central | 2025-12-22 | N/A | 5.4 MEDIUM |
|
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues.
Please note: an attacker must first obtain authentication to Apex Central on the target system in order to exploit this vulnerability.
This is similar to, but not identical to CVE-2023-32536.
|
|||||
| CVE-2023-52327 | 1 Trendmicro | 1 Apex Central | 2025-12-22 | N/A | 6.1 MEDIUM |
|
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers.
Please note this vulnerability is similar, but not identical to CVE-2023-52328.
|
|||||
| CVE-2023-32605 | 1 Trendmicro | 1 Apex Central | 2025-12-22 | N/A | 5.4 MEDIUM |
|
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues.
Please note: an attacker must first obtain authentication to Apex Central on the target system in order to exploit this vulnerability.
This is similar to, but not identical to CVE-2023-32604.
|
|||||
| CVE-2023-32532 | 1 Trendmicro | 1 Apex Central | 2025-12-22 | N/A | 6.1 MEDIUM |
|
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers.
This is similar to, but not identical to CVE-2023-32531 through 32535.
|
|||||
| CVE-2023-32534 | 1 Trendmicro | 1 Apex Central | 2025-12-22 | N/A | 6.1 MEDIUM |
|
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers.
This is similar to, but not identical to CVE-2023-32531 through 32535.
|
|||||
| CVE-2023-32536 | 1 Trendmicro | 1 Apex Central | 2025-12-22 | N/A | 5.4 MEDIUM |
|
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues.
Please note: an attacker must first obtain authentication to Apex Central on the target system in order to exploit this vulnerability.
This is similar to, but not identical to CVE-2023-32537.
|
|||||
| CVE-2023-32604 | 1 Trendmicro | 1 Apex Central | 2025-12-22 | N/A | 5.4 MEDIUM |
|
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues.
Please note: an attacker must first obtain authentication to Apex Central on the target system in order to exploit this vulnerability.
This is similar to, but not identical to CVE-2023-32605.
|
|||||
| CVE-2025-67906 | 1 Misp | 1 Misp | 2025-12-21 | N/A | 5.4 MEDIUM |
|
In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.
|
|||||
| CVE-2025-10044 | 2025-12-19 | N/A | 4.3 MEDIUM | ||
|
A flaw was found in Keycloak. Keycloak’s account console and other pages accept arbitrary text in the error_description query parameter. This text is directly rendered in error pages without validation or sanitization. While HTML encoding prevents XSS, an attacker can craft URLs with misleading messages (e.g., fake support phone numbers or URLs), which are displayed within the trusted Keycloak UI. This creates a phishing vector, potentially tricking users into contacting malicious actors.
|
|||||
| CVE-2025-8427 | 1 Fastlinemedia | 1 Beaver Builder | 2025-12-19 | N/A | 6.4 MEDIUM |
|
The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and including, 2.9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
|
|||||
| CVE-2018-7205 | 1 Kentico | 1 Xperience | 2025-12-19 | 3.5 LOW | 4.8 MEDIUM |
|
Reflected Cross-Site Scripting vulnerability in "Design" on "Edit device layout" in Kentico 9 through 11 allows remote attackers to execute malicious JavaScript via a malicious devicename parameter in a link that is entered via the "Pages -> Edit template properties -> Device Layouts -> Create device layout (and edit created device layout) -> Design" screens. NOTE: the vendor has responded that there is intended functionality for authorized users to edit and update ascx code layout
|
|||||
| CVE-2021-46163 | 1 Kentico | 1 Xperience | 2025-12-19 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Kentico Xperience 13.0.44 allows XSS via an XML document to the Media Libraries subsystem.
|
|||||
| CVE-2018-6842 | 1 Kentico | 1 Xperience | 2025-12-19 | 3.5 LOW | 5.4 MEDIUM |
|
Kentico 10 before 10.0.50 and 11 before 11.0.3 has XSS in which a crafted URL results in improper construction of a system page.
|
|||||
| CVE-2020-24794 | 1 Kentico | 1 Xperience | 2025-12-19 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Cross Site Scripting (XSS) vulnerability in Kentico before 12.0.75.
|
|||||
| CVE-2025-67344 | 1 Jishenghua | 1 Jsherp | 2025-12-19 | N/A | 4.6 MEDIUM |
|
jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint.
|
|||||
| CVE-2025-67341 | 1 Jishenghua | 1 Jsherp | 2025-12-19 | N/A | 4.6 MEDIUM |
|
jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to upload PDF files containing XSS payloads. Additionally, these PDF files can be accessed via static URLs, making them accessible to all users.
|
|||||
| CVE-2025-14046 | 1 Github | 1 Enterprise Server | 2025-12-19 | N/A | 6.1 MEDIUM |
|
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to inject DOM elements with IDs that collided with server-initialized data islands. These collisions could overwrite or shadow critical application state objects used by certain Project views, leading to unintended server-side POST requests or other unauthorized backend interactions. Successful exploitation requires an attacker to have access to the target GitHub Enterpris ...
Show More |
|||||
| CVE-2025-66574 | 1 Compassplustechnologies | 1 Tranzaxis | 2025-12-19 | N/A | 5.4 MEDIUM |
|
TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint, allowing attackers to steal session cookies and potentially escalate privileges.
|
|||||