Vulnerabilities (CVE)

Filtered by CWE-79
Total 39238 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-25017 1 Elastic 1 Kibana 2025-10-30 N/A 8.2 HIGH
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)
CVE-2025-25018 1 Elastic 1 Kibana 2025-10-30 N/A 8.7 HIGH
Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)
CVE-2025-52620 1 Hcltech 1 Bigfix Saas 2025-10-29 N/A 4.3 MEDIUM
HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload functionality inadequately validated the submitted image format.
CVE-2025-58747 1 Langgenius 1 Dify 2025-10-29 N/A 6.1 MEDIUM
Dify is an LLM application development platform. In Dify versions through 1.9.1, the MCP OAuth component is vulnerable to cross-site scripting when a victim connects to an attacker-controlled remote MCP server. The vulnerability exists in the OAuth flow implementation where the authorization_url provided by a remote MCP server is directly passed to window.open without validation or sanitization. An attacker can craft a malicious MCP server that returns a JavaScript URI (such as javascript:alert(1)) in the authorization_url field, which is then executed when the victim attempts to connect to the MCP server. This allows the attacker to execute arbitrary JavaScript in the context of the Dify application.
CVE-2025-8681 1 Pega 1 Pega Platform 2025-10-29 N/A 5.5 MEDIUM
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component.  Requires a high privileged user with a developer role.
CVE-2023-7143 1 Fabian 1 Client Details System 2025-10-29 3.3 LOW 2.4 LOW
A vulnerability was found in code-projects Client Details System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/regester.php. The manipulation of the argument fname/lname/email/contact leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-249146 is the identifier assigned to this vulnerability.
CVE-2022-41299 1 Ibm 1 Transformation Advisor 2025-10-29 N/A 4.4 MEDIUM
IBM Cloud Transformation Advisor 2.0.1 through 3.3.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 237214.
CVE-2025-60302 1 Fabian 1 Client Details System 2025-10-29 N/A 6.1 MEDIUM
code-projects Client Details System 1.0 is vulnerable to Cross Site Scripting (XSS). When adding customer information, the client details system fills in malicious JavaScript code in the username field.
CVE-2024-30147 1 Hcltech 1 Leap 2025-10-29 N/A 6.5 MEDIUM
Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.
CVE-2024-30114 1 Hcltech 1 Leap 2025-10-29 N/A 3.7 LOW
Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.
CVE-2024-30113 1 Hcltech 1 Leap 2025-10-29 N/A 6.3 MEDIUM
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
CVE-2023-37534 1 Hcltech 1 Leap 2025-10-29 N/A 7.1 HIGH
Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.
CVE-2022-44759 1 Hcltech 1 Leap 2025-10-29 N/A 4.6 MEDIUM
Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.
CVE-2024-12211 1 Pega 1 Pega Platform 2025-10-29 N/A 5.4 MEDIUM
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.
CVE-2024-39594 1 Sap 2 Business Warehouse, Business Warehouse Virtual Comp 2025-10-29 N/A 6.1 MEDIUM
SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled inputs, resulting in Reflected Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause low impact on the confidentiality and integrity of the application.
CVE-2021-31693 1 10web 1 Photo Gallery 2025-10-29 N/A 6.1 MEDIUM
The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and type_0 for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, and CVE-2021-46889. NOTE: VMware information, previously connected to this CVE ID because of a typo, is at CVE-2022-31693.
CVE-2024-3575 1 Mindsdb 1 Mindsdb 2025-10-29 N/A 6.1 MEDIUM
Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb
CVE-2024-5410 1 Oringnet 2 Iap-420, Iap-420 Firmware 2025-10-29 N/A 5.4 MEDIUM
Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.
CVE-2024-30112 1 Hcltech 1 Connections 2025-10-28 N/A 5.4 MEDIUM
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise user's account then launch other attacks.
CVE-2024-39595 1 Sap 2 Business Warehouse, Business Warehouse Virtual Comp 2025-10-28 N/A 5.4 MEDIUM
SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled inputs, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows users to modify website content and on successful exploitation, an attacker can cause low impact to the confidentiality and integrity of the application.