Vulnerabilities (CVE)

Filtered by CWE-79
Total 45351 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-55888 1 Ard 1 Gec En Ligne 2026-07-05 N/A 7.3 HIGH
Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can intercept the Ajax response and inject malicious JavaScript into the accountName field. This input is not properly sanitized or encoded when rendered, allowing script execution in the context of users browsers. This flaw could lead to session hijacking, cookie theft, and other malicious actions.
CVE-2025-55887 1 Ard 1 Gec En Ligne 2026-07-05 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD. The vulnerability exists in the transactionID GET parameter on the transaction confirmation page. Due to improper input validation and output encoding, an attacker can inject malicious JavaScript code that is executed in the context of a user s browser. This can lead to session hijacking, theft of cookies, and other malicious actions performed on behalf of the victim.
CVE-2025-52204 2026-07-05 N/A 6.1 MEDIUM
A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCustomerInterface parameter
CVE-2025-52161 1 Scholl 1 Weblication Cms 2026-07-05 N/A 9.8 CRITICAL
Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2021-42193 1 Nopcommerce 1 Nopcommerce 2026-07-05 N/A 6.1 MEDIUM
nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload fires.
CVE-2025-51629 2026-07-05 N/A 8.8 HIGH
A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Temp parameter.
CVE-2025-51624 2026-07-05 N/A 7.6 HIGH
Cross-site scripting (XSS) vulnerability in Zone Bitaqati thru 3.4.0.
CVE-2024-50803 1 Redaxo 1 Redaxo 2026-07-05 N/A 5.4 MEDIUM
The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allows a remote attacker to escalate privileges
CVE-2024-50659 1 Ipublishmedia 1 Adportal 2026-07-05 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability iPublish Media Solutions AdPortal 3.0.39 allows a remote attacker to escalate privileges via the shippingAsBilling parameter in updateuserinfo.html.
CVE-2024-48197 2026-07-05 N/A 4.7 MEDIUM
Cross Site Scripting vulnerability in Audiocodes MP-202b v.4.4.3 allows a remote attacker to escalate privileges via the login page of the web interface.
CVE-2024-42831 2026-07-05 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a user via injecting a crafted payload into the dialog parameter at wrapper_dialog.php.
CVE-2024-41446 1 Alkacon 1 Opencms 2026-07-05 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the image parameter under the Create/Modify article function.
CVE-2024-34335 1 Ordat 1 Ordat.erp 2026-07-05 N/A 6.1 MEDIUM
ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page.
CVE-2025-67316 1 Heytap 1 Internet Browser 2026-07-05 N/A 5.4 MEDIUM
An issue in realme Internet browser v.45.13.4.1 allows a remote attacker to execute arbitrary code via a crafted webpage in the built-in HeyTap/ColorOS browser. NOTE: The supplier is currently disputing this finding and the record is under review.
CVE-2025-56320 2026-07-05 N/A 5.4 MEDIUM
CobbleStone Enterprise Contract Management Portal v.22.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) in its chat box component. This allows a remote attacker to execute arbitrary code. NOTE: the Supplier reports that this is "Present only in an obsolete, unsupported version no longer in circulation."
CVE-2024-55488 1 Umbraco 1 Umbraco Cms 2026-07-05 N/A 6.5 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: This has been disputed by the vendor since this potential attack is only possible via authenticated users who have been manually allowed access to the CMS. There was a deliberate decision made not to apply HTML sanitization at the product level.
CVE-2026-50767 1 Koha 1 Koha 2026-07-05 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the item type check-in message field (checkinmsg).
CVE-2026-50766 1 Koha 1 Koha 2026-07-05 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with edit_items permission to inject arbitrary web scripts via the item public notes field (items.itemnotes).
CVE-2026-50765 1 Koha 1 Koha 2026-07-05 N/A 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the restriction type label (display_text field).
CVE-2026-36906 2026-07-05 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in iotgateway v.3.0.1 allows a remote attacker to execute arbitrary code via the Log Record Function