Vulnerabilities (CVE)

Filtered by CWE-79
Total 45373 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-40487 1 Processwire 1 Processwire 2026-07-09 N/A 6.1 MEDIUM
ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users and Search Pages function. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via injection of a crafted payload.
CVE-2022-40440 1 Jgraph 1 Mxgraph 2026-07-09 N/A 6.1 MEDIUM
mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.
CVE-2022-40435 1 Employee Performance Evaluation System Project 1 Employee Performance Evaluation System 2026-07-09 N/A 4.8 MEDIUM
Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Departments and Designations module.
CVE-2022-40434 1 Softr 1 Softr 2026-07-09 N/A 9.8 CRITICAL
Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.
CVE-2022-40047 1 Flatpress 1 Flatpress 2026-07-09 N/A 5.4 MEDIUM
Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /flatpress/admin.php.
CVE-2022-40029 1 Simple Task Managing System Project 1 Simple Task Managing System 2026-07-09 N/A 4.8 MEDIUM
SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newProjectValidation.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the shortName parameter.
CVE-2022-40028 1 Simple Task Managing System Project 1 Simple Task Managing System 2026-07-09 N/A 4.8 MEDIUM
SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newProjectValidation.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fullName parameter.
CVE-2022-40027 1 Simple Task Managing System Project 1 Simple Task Managing System 2026-07-09 N/A 6.1 MEDIUM
SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newTask.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the shortName parameter.
CVE-2022-40011 1 Typora 1 Typora 2026-07-09 N/A 6.1 MEDIUM
Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then used at a victim's origin.
CVE-2022-38902 1 Liferay 2 Dxp, Liferay Portal 2026-07-09 N/A 5.4 MEDIUM
A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.
CVE-2022-38901 1 Liferay 2 Dxp, Liferay Portal 2026-07-09 N/A 5.4 MEDIUM
A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.
CVE-2022-38553 1 Creativeitem 1 Academy Learning Management System 2026-07-09 N/A 6.1 MEDIUM
Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.
CVE-2022-37830 1 Webjet 1 Webjet Cms 2026-07-09 N/A 9.6 CRITICAL
Interway a.s WebJET CMS 8.6.896 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-37775 1 Genesys 1 Pureconnect 2026-07-09 N/A 6.1 MEDIUM
Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History via the participant -> name JSON POST parameter.
CVE-2022-37721 1 Pyrocms 1 Pyrocms 2026-07-09 N/A 9.0 CRITICAL
PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation.
CVE-2022-37720 1 Orchardcore 1 Orchard Cms 2026-07-09 N/A 9.0 CRITICAL
Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation when the malicious blog post is loaded in the victim's browser.
CVE-2022-37251 1 Craftcms 1 Craft Cms 2026-07-09 N/A 5.4 MEDIUM
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.
CVE-2022-36533 2 Linux, Syncovery 2 Linux Kernel, Syncovery 2026-07-09 N/A 5.4 MEDIUM
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2022-36530 1 Rageframe 1 Rageframe 2026-07-09 N/A 6.1 MEDIUM
An issue was discovered in rageframe2 2.6.37. There is a XSS vulnerability in the user agent related parameters of the info.php page.
CVE-2022-36180 1 Fusiondirectory 1 Fusiondirectory 2026-07-09 N/A 9.6 CRITICAL
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.