Vulnerabilities (CVE)

Filtered by CWE-79
Total 45372 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-28598 1 Frappe 1 Erpnext 2026-07-09 N/A 6.1 MEDIUM
Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2022-28102 1 Php Mysql Admin Panel Generator Project 1 Php Mysql Admin Panel Generator 2026-07-09 3.5 LOW 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php.
CVE-2022-28094 1 Online Sports Complex Booking System Project 1 Online Sports Complex Booking System 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.
CVE-2022-28078 1 Home Owners Collection Management System Project 1 Home Owners Collection Management System 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.
CVE-2022-28077 1 Home Owners Collection Management System Project 1 Home Owners Collection Management System 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.
CVE-2022-27979 1 Tooljet 1 Tooljet 2026-07-09 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment Body component.
CVE-2022-26644 1 Oretnom23 1 Banking System 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via parameters on user profile, system_info and accounts management.
CVE-2022-26596 1 Liferay 2 Digital Experience Platform, Liferay Portal 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 8, allows remote attackers to inject arbitrary web script or HTML via web content template names.
CVE-2022-26594 1 Liferay 1 Liferay Portal 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms module's form builder, or (2) App Builder module's object form view's form builder.
CVE-2022-26593 1 Liferay 2 Digital Experience Platform, Liferay Portal 2026-07-09 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the name of a asset category.
CVE-2022-26263 1 Yonyou 1 U8\+ 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.
CVE-2022-26244 1 Hospital\'s Patient Records Management System Project 1 Hospital\'s Patient Records Management System 2026-07-09 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "special" field.
CVE-2022-26197 1 Joget 1 Joget Dx 2026-07-09 3.5 LOW 5.4 MEDIUM
Joget DX 7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Datalist table.
CVE-2022-25585 1 Unioncms Project 1 Unioncms 2026-07-09 3.5 LOW 5.4 MEDIUM
Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.
CVE-2022-25574 1 Douco 1 Douphp 2026-07-09 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file.
CVE-2022-25022 1 Htmly 1 Htmly 2026-07-09 3.5 LOW 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.
CVE-2022-25020 1 Pluxml 1 Pluxml 2026-07-09 3.5 LOW 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.
CVE-2022-24654 1 Intelbras 2 Ata 200, Ata 200 Firmware 2026-07-09 N/A 5.4 MEDIUM
Authenticated stored cross-site scripting (XSS) vulnerability in "Field Server Address" field in INTELBRAS ATA 200 Firmware 74.19.10.21 allows attackers to inject JavaScript code through a crafted payload.
CVE-2022-24573 1 Element-it 1 Http Commander 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unauthenticated users to get admin access by injecting a malicious script in the User-Agent field.
CVE-2022-24238 1 Aceware 1 Aceweb Online Portal 2026-07-09 4.3 MEDIUM 6.1 MEDIUM
ACEweb Online Portal 3.5.065 was discovered to contain a cross-site scripting (XSS) vulnerability via the txtNmName1 parameter in person.awp.