Vulnerabilities (CVE)

Filtered by CWE-79
Total 45372 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-35501 1 Amasty 1 Blog Pro 2026-07-09 N/A 5.4 MEDIUM
Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the duplicate post function.
CVE-2022-35500 1 Amasty 1 Blog Pro 2026-07-09 N/A 5.4 MEDIUM
Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality.
CVE-2022-35155 1 Phpgurukul 1 Bus Pass Management System 2026-07-09 N/A 6.1 MEDIUM
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter.
CVE-2022-35131 1 Joplinapp 1 Joplin 2026-07-09 N/A 9.0 CRITICAL
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
CVE-2022-35118 1 Pyrocms 1 Pyrocms 2026-07-09 N/A 6.1 MEDIUM
PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
CVE-2022-34611 1 Online Fire Reporting System Project 1 Online Fire Reporting System 2026-07-09 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "Contac #" text field.
CVE-2022-33098 1 Magnolia-cms 1 Magnolia Cms 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted SVG document, with JavaScript, for a profile picture.
CVE-2022-33075 1 Phpgurukul 1 Zoo Management System 2026-07-09 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via unspecified vectors.
CVE-2022-33009 1 Lightcms Project 1 Lightcms 2026-07-09 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploading a crafted PDF file.
CVE-2022-31904 1 Uberrider 1 Mediacenter 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
EGT-Kommunikationstechnik UG Mediacenter before v2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Online_Update.php.
CVE-2022-31897 1 Phpgurukul 1 Zoo Management System 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?msg=.
CVE-2022-31358 1 Proxmox 1 Virtual Environment 2026-07-09 N/A 9.0 CRITICAL
A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.
CVE-2022-29649 1 Qsmart Next Project 1 Qsmart Next 2026-07-09 N/A 6.1 MEDIUM
Qsmart Next v4.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2022-29005 1 Phpgurukul 1 Online Birth Certificate System 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.
CVE-2022-29004 1 Phpgurukul 1 E-diary Management System 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.
CVE-2022-28982 1 Liferay 2 Dxp, Liferay Portal 2026-07-09 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service pack 3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name of a tag.
CVE-2022-28980 1 Liferay 2 Dxp, Liferay Portal 2026-07-09 N/A 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows attackers to execute arbitrary web scripts or HTML via parameters with the filter_ prefix.
CVE-2022-28979 1 Liferay 3 Digital Experience Platform, Dxp, Liferay Portal 2026-07-09 N/A 6.1 MEDIUM
Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 was discovered to contain a cross-site scripting (XSS) vulnerability in the Portal Search module's Custom Facet widget. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Parameter Name text field.
CVE-2022-28978 1 Liferay 3 Digital Experience Platform, Dxp, Liferay Portal 2026-07-09 N/A 5.4 MEDIUM
Stored cross-site scripting (XSS) vulnerability in the Site module's user membership administration page in Liferay Portal 7.0.1 through 7.4.1, and Liferay DXP 7.0 before fix pack 102, 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the a user's name.
CVE-2022-28975 1 Infoblox 1 Nios 2026-07-09 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the VLAN View Name field.