Total
45373 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-40487 | 1 Processwire | 1 Processwire | 2026-07-09 | N/A | 6.1 MEDIUM |
| ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users and Search Pages function. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via injection of a crafted payload. | |||||
| CVE-2022-40440 | 1 Jgraph | 1 Mxgraph | 2026-07-09 | N/A | 6.1 MEDIUM |
| mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function. | |||||
| CVE-2022-40435 | 1 Employee Performance Evaluation System Project | 1 Employee Performance Evaluation System | 2026-07-09 | N/A | 4.8 MEDIUM |
| Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Departments and Designations module. | |||||
| CVE-2022-40434 | 1 Softr | 1 Softr | 2026-07-09 | N/A | 9.8 CRITICAL |
| Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page. | |||||
| CVE-2022-40047 | 1 Flatpress | 1 Flatpress | 2026-07-09 | N/A | 5.4 MEDIUM |
| Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /flatpress/admin.php. | |||||
| CVE-2022-40029 | 1 Simple Task Managing System Project | 1 Simple Task Managing System | 2026-07-09 | N/A | 4.8 MEDIUM |
| SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newProjectValidation.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the shortName parameter. | |||||
| CVE-2022-40028 | 1 Simple Task Managing System Project | 1 Simple Task Managing System | 2026-07-09 | N/A | 4.8 MEDIUM |
| SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newProjectValidation.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fullName parameter. | |||||
| CVE-2022-40027 | 1 Simple Task Managing System Project | 1 Simple Task Managing System | 2026-07-09 | N/A | 6.1 MEDIUM |
| SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newTask.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the shortName parameter. | |||||
| CVE-2022-40011 | 1 Typora | 1 Typora | 2026-07-09 | N/A | 6.1 MEDIUM |
| Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then used at a victim's origin. | |||||
| CVE-2022-38902 | 1 Liferay | 2 Dxp, Liferay Portal | 2026-07-09 | N/A | 5.4 MEDIUM |
| A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic. | |||||
| CVE-2022-38901 | 1 Liferay | 2 Dxp, Liferay Portal | 2026-07-09 | N/A | 5.4 MEDIUM |
| A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file. | |||||
| CVE-2022-38553 | 1 Creativeitem | 1 Academy Learning Management System | 2026-07-09 | N/A | 6.1 MEDIUM |
| Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter. | |||||
| CVE-2022-37830 | 1 Webjet | 1 Webjet Cms | 2026-07-09 | N/A | 9.6 CRITICAL |
| Interway a.s WebJET CMS 8.6.896 is vulnerable to Cross Site Scripting (XSS). | |||||
| CVE-2022-37775 | 1 Genesys | 1 Pureconnect | 2026-07-09 | N/A | 6.1 MEDIUM |
| Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History via the participant -> name JSON POST parameter. | |||||
| CVE-2022-37721 | 1 Pyrocms | 1 Pyrocms | 2026-07-09 | N/A | 9.0 CRITICAL |
| PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation. | |||||
| CVE-2022-37720 | 1 Orchardcore | 1 Orchard Cms | 2026-07-09 | N/A | 9.0 CRITICAL |
| Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation when the malicious blog post is loaded in the victim's browser. | |||||
| CVE-2022-37251 | 1 Craftcms | 1 Craft Cms | 2026-07-09 | N/A | 5.4 MEDIUM |
| Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts. | |||||
| CVE-2022-36533 | 2 Linux, Syncovery | 2 Linux Kernel, Syncovery | 2026-07-09 | N/A | 5.4 MEDIUM |
| Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability. | |||||
| CVE-2022-36530 | 1 Rageframe | 1 Rageframe | 2026-07-09 | N/A | 6.1 MEDIUM |
| An issue was discovered in rageframe2 2.6.37. There is a XSS vulnerability in the user agent related parameters of the info.php page. | |||||
| CVE-2022-36180 | 1 Fusiondirectory | 1 Fusiondirectory | 2026-07-09 | N/A | 9.6 CRITICAL |
| Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106. | |||||
