Vulnerabilities (CVE)

Filtered by CWE-79
Total 45382 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-27666 1 Auto Dealer Management System Project 1 Auto Dealer Management System 2026-07-09 N/A 6.1 MEDIUM
Auto Dealer Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the name parameter at /classes/SystemSettings.php?f=update_settings.
CVE-2023-27237 1 Lavalite 1 Lavalite 2026-07-09 N/A 6.1 MEDIUM
LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack.
CVE-2023-27000 1 Netscout 1 Ngeniusone 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion List page(s).
CVE-2023-26998 1 Netscout 1 Ngeniusone 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the creator parameter of the Alert Configuration page.
CVE-2023-26961 1 Alteryx 1 Alteryx Server 2026-07-09 N/A 4.8 MEDIUM
Alteryx Server 2022.1.1.42590 does not employ file type verification for uploaded files. This vulnerability allows attackers to upload arbitrary files (e.g., JavaScript content for stored XSS) via the type field in a JSON document within a PUT /gallery/api/media request.
CVE-2023-25309 1 Fetlife 1 Rollout-ui 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui version 0.5, allows attackers to execute arbitrary code via a crafted url to the delete a feature functionality.
CVE-2023-25292 1 Group-office 1 Group Office 2026-07-09 N/A 6.1 MEDIUM
Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive information via the GO_LANGUAGE cookie.
CVE-2023-24721 1 Liveaction 1 Livesp 2026-07-09 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary web scripts or HTML.
CVE-2023-24282 1 Poly 2 Trio 8800, Trio 8800 Firmware 2026-07-09 N/A 5.4 MEDIUM
An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a crafted ringtone file.
CVE-2023-23326 1 Avantfax 1 Avantfax 2026-07-09 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability exists in AvantFAX 3.3.7. An authenticated low privilege user can inject arbitrary Javascript into their e-mail address which is executed when an administrator logs into AvantFAX to view the admin dashboard. This may result in stealing an administrator's session cookie and hijacking their session.
CVE-2023-22985 1 Simple Guestbook Management System Project 1 Simple Guestbook Management System 2026-07-09 N/A 6.1 MEDIUM
Sourcecodester Simple Guestbook Management System version 1 is vulnerable to Cross Site Scripting (XSS) via Name, Referrer, Location, and Comments.
CVE-2022-48111 1 Siri-informatica 1 Wi400 2026-07-09 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the check_login function of SIPE s.r.l WI400 between version 8 and 11 included allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the f parameter.
CVE-2022-48085 1 Softr 1 Softr 2026-07-09 N/A 5.4 MEDIUM
Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter.
CVE-2022-44962 1 Webtareas Project 1 Webtareas 2026-07-09 N/A 5.4 MEDIUM
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /calendar/viewcalendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject field.
CVE-2022-44961 1 Webtareas Project 1 Webtareas 2026-07-09 N/A 5.4 MEDIUM
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /forums/editforum.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
CVE-2022-44960 1 Webtareas Project 1 Webtareas 2026-07-09 N/A 5.4 MEDIUM
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /general/search.php?searchtype=simple. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search field.
CVE-2022-44959 1 Webtareas Project 1 Webtareas 2026-07-09 N/A 5.4 MEDIUM
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /meetings/listmeetings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
CVE-2022-44957 1 Webtareas Project 1 Webtareas 2026-07-09 N/A 5.4 MEDIUM
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /clients/listclients.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
CVE-2022-44956 1 Webtareas Project 1 Webtareas 2026-07-09 N/A 5.4 MEDIUM
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /projects/listprojects.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
CVE-2022-44955 1 Webtareas Project 1 Webtareas 2026-07-09 N/A 5.4 MEDIUM
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the Chat function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Messages field.