Total
45351 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-55888 | 1 Ard | 1 Gec En Ligne | 2026-07-05 | N/A | 7.3 HIGH |
| Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can intercept the Ajax response and inject malicious JavaScript into the accountName field. This input is not properly sanitized or encoded when rendered, allowing script execution in the context of users browsers. This flaw could lead to session hijacking, cookie theft, and other malicious actions. | |||||
| CVE-2025-55887 | 1 Ard | 1 Gec En Ligne | 2026-07-05 | N/A | 6.1 MEDIUM |
| Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD. The vulnerability exists in the transactionID GET parameter on the transaction confirmation page. Due to improper input validation and output encoding, an attacker can inject malicious JavaScript code that is executed in the context of a user s browser. This can lead to session hijacking, theft of cookies, and other malicious actions performed on behalf of the victim. | |||||
| CVE-2025-52204 | 2026-07-05 | N/A | 6.1 MEDIUM | ||
| A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCustomerInterface parameter | |||||
| CVE-2025-52161 | 1 Scholl | 1 Weblication Cms | 2026-07-05 | N/A | 9.8 CRITICAL |
| Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vulnerability. | |||||
| CVE-2021-42193 | 1 Nopcommerce | 1 Nopcommerce | 2026-07-05 | N/A | 6.1 MEDIUM |
| nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload fires. | |||||
| CVE-2025-51629 | 2026-07-05 | N/A | 8.8 HIGH | ||
| A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Temp parameter. | |||||
| CVE-2025-51624 | 2026-07-05 | N/A | 7.6 HIGH | ||
| Cross-site scripting (XSS) vulnerability in Zone Bitaqati thru 3.4.0. | |||||
| CVE-2024-50803 | 1 Redaxo | 1 Redaxo | 2026-07-05 | N/A | 5.4 MEDIUM |
| The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileges | |||||
| CVE-2024-50659 | 1 Ipublishmedia | 1 Adportal | 2026-07-05 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability iPublish Media Solutions AdPortal 3.0.39 allows a remote attacker to escalate privileges via the shippingAsBilling parameter in updateuserinfo.html. | |||||
| CVE-2024-48197 | 2026-07-05 | N/A | 4.7 MEDIUM | ||
| Cross Site Scripting vulnerability in Audiocodes MP-202b v.4.4.3 allows a remote attacker to escalate privileges via the login page of the web interface. | |||||
| CVE-2024-42831 | 2026-07-05 | N/A | 6.1 MEDIUM | ||
| A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a user via injecting a crafted payload into the dialog parameter at wrapper_dialog.php. | |||||
| CVE-2024-41446 | 1 Alkacon | 1 Opencms | 2026-07-05 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the image parameter under the Create/Modify article function. | |||||
| CVE-2024-34335 | 1 Ordat | 1 Ordat.erp | 2026-07-05 | N/A | 6.1 MEDIUM |
| ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page. | |||||
| CVE-2025-67316 | 1 Heytap | 1 Internet Browser | 2026-07-05 | N/A | 5.4 MEDIUM |
| An issue in realme Internet browser v.45.13.4.1 allows a remote attacker to execute arbitrary code via a crafted webpage in the built-in HeyTap/ColorOS browser. NOTE: The supplier is currently disputing this finding and the record is under review. | |||||
| CVE-2025-56320 | 2026-07-05 | N/A | 5.4 MEDIUM | ||
| CobbleStone Enterprise Contract Management Portal v.22.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) in its chat box component. This allows a remote attacker to execute arbitrary code. NOTE: the Supplier reports that this is "Present only in an obsolete, unsupported version no longer in circulation." | |||||
| CVE-2024-55488 | 1 Umbraco | 1 Umbraco Cms | 2026-07-05 | N/A | 6.5 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: This has been disputed by the vendor since this potential attack is only possible via authenticated users who have been manually allowed access to the CMS. There was a deliberate decision made not to apply HTML sanitization at the product level. | |||||
| CVE-2026-50767 | 1 Koha | 1 Koha | 2026-07-05 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the item type check-in message field (checkinmsg). | |||||
| CVE-2026-50766 | 1 Koha | 1 Koha | 2026-07-05 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with edit_items permission to inject arbitrary web scripts via the item public notes field (items.itemnotes). | |||||
| CVE-2026-50765 | 1 Koha | 1 Koha | 2026-07-05 | N/A | 6.1 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the restriction type label (display_text field). | |||||
| CVE-2026-36906 | 2026-07-05 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in iotgateway v.3.0.1 allows a remote attacker to execute arbitrary code via the Log Record Function | |||||
