Vulnerabilities (CVE)

Filtered by CWE-79
Total 42538 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-0947 1 Bordeaux-metropole 1 At Internet Piano Analytics 2026-02-11 N/A 4.8 MEDIUM
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet Piano Analytics allows Cross-Site Scripting (XSS).This issue affects AT Internet Piano Analytics: from 0.0.0 before 1.0.1, from 2.0.0 before 2.3.1.
CVE-2026-2064 1 Portabilis 1 I-educar 2026-02-11 4.0 MEDIUM 3.5 LOW
A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/meusdadod.php of the component User Data Page. Such manipulation of the argument File leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-21529 1 Microsoft 1 Azure Hdinsight 2026-02-11 N/A 5.7 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network.
CVE-2023-36881 1 Microsoft 1 Azure Hdinsight 2026-02-11 N/A 4.5 MEDIUM
Azure Apache Ambari Spoofing Vulnerability
CVE-2023-38188 1 Microsoft 1 Azure Hdinsight 2026-02-11 N/A 4.5 MEDIUM
Azure Apache Hadoop Spoofing Vulnerability
CVE-2023-35394 1 Microsoft 1 Azure Hdinsight 2026-02-11 N/A 4.6 MEDIUM
Azure HDInsight Jupyter Notebook Spoofing Vulnerability
CVE-2023-35393 1 Microsoft 1 Azure Hdinsight 2026-02-11 N/A 4.5 MEDIUM
Azure Apache Hive Spoofing Vulnerability
CVE-2023-36877 1 Microsoft 1 Azure Hdinsight 2026-02-11 N/A 4.5 MEDIUM
Azure Apache Oozie Spoofing Vulnerability
CVE-2023-23408 1 Microsoft 1 Azure Hdinsight 2026-02-11 N/A 4.5 MEDIUM
Azure Apache Ambari Spoofing Vulnerability
CVE-2025-67855 1 Moodle 1 Moodle 2026-02-11 N/A 5.4 MEDIUM
A flaw was found in mooodle. A remote attacker could exploit a reflected Cross-Site Scripting (XSS) vulnerability in the policy tool return URL. This vulnerability arises from insufficient sanitization of URL parameters, allowing attackers to inject malicious scripts through specially crafted links. Successful exploitation could lead to information disclosure or arbitrary client-side script execution within the user's browser.
CVE-2025-67850 1 Moodle 1 Moodle 2026-02-11 N/A 7.3 HIGH
A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users view these expressions, the malicious code would execute in their web browsers, potentially compromising their data or leading to unauthorized actions.
CVE-2025-67849 1 Moodle 1 Moodle 2026-02-11 N/A 7.3 HIGH
A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen, or the user interface could be manipulated.
CVE-2025-65923 1 Frappe 1 Erpnext 2026-02-11 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1 when using the Update Existing Recordsoption. An attacker can embed malicious JavaScript code into a CSV field, which is then stored in the database and executed whenever the affected record is viewed by a user within the ERPNext web interface. This exposure may allow an attacker to compromise user sessions or perform unauthorized actions under the context of a victim's account.
CVE-2025-69848 1 Netbox 1 Netbox 2026-02-11 N/A 5.4 MEDIUM
NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object names are included in HTML error messages without proper escaping. This allows user-controlled content to be rendered in the web interface when a delete operation fails due to protected relationships, potentially enabling execution of arbitrary client-side code in the context of a privileged user.
CVE-2025-70849 1 Stefanprodan 1 Podinfo 2026-02-11 N/A 6.1 MEDIUM
Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST request to the /store endpoint. The application renders uploaded content without a restrictive Content-Security-Policy (CSP) or adequate Content-Type validation, leading to Stored Cross-Site Scripting (XSS).
CVE-2026-1804 2026-02-11 N/A 6.4 MEDIUM
The WDES Responsive Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdes-popup-title' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2018-25157 2026-02-11 N/A 6.4 MEDIUM
Phraseanet 4.0.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through crafted file names during document uploads. Attackers can upload files with embedded SVG scripts that execute in the browser, potentially stealing cookies or redirecting users when the file is viewed.
CVE-2026-1809 2026-02-11 N/A 6.4 MEDIUM
The HTML Tag Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-0724 2026-02-11 N/A 4.4 MEDIUM
The WPlyr Media Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_wplyr_accent_color' parameter in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2019-25315 2026-02-11 N/A 6.4 MEDIUM
WordPress Server Log Viewer 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unfiltered log file paths. Attackers can add log files with embedded XSS payloads that will execute when viewed in the WordPress admin interface.