Vulnerabilities (CVE)

Filtered by CWE-79
Total 45382 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-36223 1 Bbs-go 1 Bbs-go 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary code via a crafted payload to the announcements parameter in the settings function.
CVE-2023-36222 1 Bbs-go 1 Bbs-go 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary code via a crafted payload to the comment parameter in the article function.
CVE-2023-36159 1 Oretnom23 1 Lost And Found Information System 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page.
CVE-2023-36158 1 Oretnom23 1 Toll Tax Management System 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in sourcecodester Toll Tax Management System 1.0 allows remote attackers to run arbitrary code via the First Name and Last Name fields on the My Account page.
CVE-2023-36146 1 Multilaser 2 Re170, Re170 Firmware 2026-07-09 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability was found in Multilaser RE 170 using firmware 2.2.6733.
CVE-2023-36081 1 Gatesair 2 Flexiva Fax 150w, Flexiva Fax 150w Firmware 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in GatesAIr Flexiva FM Transmitter/Exciter v.FAX 150W allows a remote attacker to execute arbitrary code via a crafted script to the web application dashboard.
CVE-2023-34840 1 Angular-ui-notification Project 1 Angular-ui-notification 2026-07-09 N/A 6.1 MEDIUM
angular-ui-notification v0.1.0, v0.2.0, and v0.3.6 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2023-33438 1 Wolterskluwer 1 Teammate\+ 2026-07-09 N/A 5.4 MEDIUM
A stored Cross-site scripting (XSS) vulnerability in Wolters Kluwer TeamMate+ 35.0.11.0 allows remote attackers to inject arbitrary web script or HTML.
CVE-2023-31868 1 Sage 1 X3 2026-07-09 N/A 5.4 MEDIUM
Sage X3 version 12.14.0.50-0 is vulnerable to Cross Site Scripting (XSS). Some parts of the Web application are dynamically built using user's inputs. Yet, those inputs are not verified nor filtered by the application, so they mathed the expected format. Therefore, when HTML/JavaScript code is injected into those fields, this code will be saved by the application and executed by the web browser of the user viewing the web page. Several injection points have been identified on the application. The major one requires the user to be authenticated with a common account, he can then target an Administrator. All others endpoints need the malicious user to be authenticated as an Administrator. Therefore, the impact is diminished.
CVE-2023-31807 1 Chamilo 1 Chamilo Lms 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the personal notes function.
CVE-2023-31806 1 Chamilo 1 Chamilo Lms 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My Progress function.
CVE-2023-31805 1 Chamilo 1 Chamilo Lms 2026-07-09 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local authenticated attacker to execute arbitrary code via the homepage function.
CVE-2023-31804 1 Chamilo 1 Chamilo Lms 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the course category parameters.
CVE-2023-31803 1 Chamilo 1 Chamilo Lms 2026-07-09 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the resource sequencing parameters.
CVE-2023-31802 1 Chamilo 1 Chamilo Lms 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skype and linedin_url parameters.
CVE-2023-31801 1 Chamilo 1 Chamilo Lms 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skills wheel parameter.
CVE-2023-31800 1 Chamilo 1 Chamilo Lms 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the forum title parameter.
CVE-2023-31799 1 Chamilo 1 Chamilo Lms 2026-07-09 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the system annnouncements parameter.
CVE-2023-30057 1 Fico 1 Origination Manager Decision 2026-07-09 N/A 5.4 MEDIUM
Multiple stored cross-site scripting (XSS) vulnerabilities in FICO Origination Manager Decision Module 4.8.1 allow attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2023-27775 1 Liveaction 1 Livesp 2026-07-09 N/A 5.4 MEDIUM
A stored HTML injection vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary code via a crafted payload.