Vulnerabilities (CVE)

Filtered by CWE-79
Total 45373 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-44944 1 Rukovoditel 1 Rukovoditel 2026-07-09 N/A 5.4 MEDIUM
Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement function at /index.php?module=help_pages/pages&entities_id=24. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.
CVE-2022-44897 1 Apollotheme 1 Ap Pagebuilder 2026-07-09 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in ApolloTheme AP PageBuilder component through 2.4.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the show_number parameter.
CVE-2022-44303 1 Resque-scheduler Project 1 Resque-scheduler 2026-07-09 N/A 6.1 MEDIUM
Resque Scheduler version 1.27.4 is vulnerable to Cross-site scripting (XSS). A remote attacker could inject javascript code to the "{schedule_job}" or "args" parameter in /resque/delayed/jobs/{schedule_job}?args={args_id} to execute javascript at client side.
CVE-2022-43321 1 Shopwind 1 Shopwind 2026-07-09 N/A 6.1 MEDIUM
Shopwind v3.4.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the component /common/library/Page.php.
CVE-2022-42993 1 Password Storage Application Project 1 Password Storage Application 2026-07-09 N/A 5.4 MEDIUM
Password Storage Application v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Setup page.
CVE-2022-42992 1 Train Scheduler App Project 1 Train Scheduler App 2026-07-09 N/A 5.4 MEDIUM
Multiple stored cross-site scripting (XSS) vulnerabilities in Train Scheduler App v1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Train Code, Train Name, and Destination text fields.
CVE-2022-42991 1 Simple Online Public Access Catalog Project 1 Simple Online Public Access Catalog 2026-07-09 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Simple Online Public Access Catalog v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Account Full Name field.
CVE-2022-42989 1 Sankhya 1 Sankhya Om 2026-07-09 N/A 9.0 CRITICAL
ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.
CVE-2022-42248 1 Qlik 1 Qlikview 2026-07-09 N/A 5.4 MEDIUM
QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functionality.
CVE-2022-42119 1 Liferay 2 Dxp, Liferay Portal 2026-07-09 N/A 5.4 MEDIUM
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Portal 7.3.5 through 7.4.2 and Liferay DXP 7.3 before update 8.
CVE-2022-42118 1 Liferay 3 Digital Experience Platform, Dxp, Liferay Portal 2026-07-09 N/A 6.1 MEDIUM
A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter.
CVE-2022-42117 1 Liferay 2 Dxp, Liferay Portal 2026-07-09 N/A 6.1 MEDIUM
A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update 6, and 7.4 before update 17 allows remote attackers to inject arbitrary web script or HTML.
CVE-2022-42116 1 Liferay 2 Dxp, Liferay Portal 2026-07-09 N/A 6.1 MEDIUM
A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web script or HTML via the (1) name, or (2) namespace parameter.
CVE-2022-42115 1 Liferay 1 Liferay Portal 2026-07-09 N/A 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 through 7.4.3.36 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the object field's `Label` text field.
CVE-2022-42114 1 Liferay 2 Dxp, Liferay Portal 2026-07-09 N/A 5.4 MEDIUM
A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and Liferay DXP 7.4 before update 37 allows remote attackers to inject arbitrary web script or HTML.
CVE-2022-42113 1 Liferay 2 Dxp, Liferay Portal 2026-07-09 N/A 6.1 MEDIUM
A Cross-site scripting (XSS) vulnerability in Document Library module in Liferay Portal 7.4.3.30 through 7.4.3.36, and Liferay DXP 7.4 update 30 through update 36 allows remote attackers to inject arbitrary web script or HTML via the `redirect` parameter.
CVE-2022-42112 1 Liferay 3 Digital Experience Platform, Dxp, Liferay Portal 2026-07-09 N/A 5.4 MEDIUM
A Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DXP 7.2 before fix pack 19, 7.3 before update 5, and DXP 7.4 before update 25 allows remote attackers to inject arbitrary web script or HTML via a crafted payload.
CVE-2022-41441 1 Reqlogic 1 Reqlogic 2026-07-09 N/A 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the POBatch and WaitDuration parameters.
CVE-2022-40841 1 Ndk-design 1 Ndkadvancedcustomizationfields 2026-07-09 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in NdkAdvancedCustomizationFields v3.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloads injected into the "htmlNodes" parameter.
CVE-2022-40840 1 Ndk-design 1 Ndkadvancedcustomizationfields 2026-07-09 N/A 6.1 MEDIUM
ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Cross Site Scripting (XSS) via createPdf.php.