Vulnerabilities (CVE)

Filtered by CWE-79
Total 45351 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-36388 2026-07-05 N/A 5.4 MEDIUM
A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to inject a malicious script payload into the User Name parameter, which is stored in the application and later rendered in the doctor s interface.
CVE-2026-36358 2026-07-05 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Juzaweb CMS v.5.0.0 allows a remote attacker via execute arbitrary code via a crafted script to the Add Banner Ads function
CVE-2026-31313 1 Feehi 1 Feehi Cms 2026-07-05 N/A 5.4 MEDIUM
An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Content field.
CVE-2026-30082 2026-07-05 N/A 6.1 MEDIUM
Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngEstate Server v11.14.0 allow attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the About application, What's news, or Release note parameters.
CVE-2025-70545 1 Belden 2 Ppc 2k05x, Ppc 2k05x Firmware 2026-07-05 N/A 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X router running firmware v1.1.9_206L. The Common Gateway Interface (CGI) component improperly handles user-supplied input, allowing a remote, unauthenticated attacker to inject arbitrary JavaScript that is persistently stored and executed when the affected interface is accessed.
CVE-2025-70365 2026-07-05 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability exists in Kiamo before 8.4 due to improper output encoding of user-supplied input in administrative interfaces. An authenticated administrative user can inject arbitrary JavaScript code that is executed in the browser of users viewing the affected pages. NOTE: the Supplier's position is that a fix for this had already been released for the 8.3.1 branch before the CVE Record was published.
CVE-2025-67291 1 Dotnetfoundation 1 Piranha Cms 2026-07-05 N/A 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field.
CVE-2025-67290 1 Dotnetfoundation 1 Piranha Cms 2026-07-05 N/A 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Excerpt field.
CVE-2025-65676 1 Classroomio 1 Classroomio 2026-07-05 N/A 5.4 MEDIUM
Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG cover images.
CVE-2025-65675 1 Classroomio 1 Classroomio 2026-07-05 N/A 5.4 MEDIUM
Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG profile pictures.
CVE-2025-65622 1 Snipeitapp 1 Snipe-it 2026-07-05 N/A 5.4 MEDIUM
Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.
CVE-2025-65621 1 Snipeitapp 1 Snipe-it 2026-07-05 N/A 5.4 MEDIUM
Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.
CVE-2025-64054 1 Fanvil 2 X210, X210 Firmware 2026-07-05 N/A 9.6 CRITICAL
A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint.
CVE-2025-64048 1 Yccms 1 Yccms 2026-07-05 N/A 6.1 MEDIUM
YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulnerability exists in the add() and getPost() functions within the ArticleAction.class.php file due to improper neutralization of user input in the article title field.
CVE-2025-64047 1 Openrapid 1 Rapidcms 2026-07-05 N/A 6.1 MEDIUM
OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php.
CVE-2025-64046 1 Openrapid 1 Rapidcms 2026-07-05 N/A 6.1 MEDIUM
OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php.
CVE-2025-63260 1 Syncfusion 1 Syncfusion 2026-07-05 N/A 5.4 MEDIUM
SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message.
CVE-2025-61078 1 Phpipam 1 Phpipam 2026-07-05 N/A 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter for the /app/admin/instructions/edit-result.php endpoint.
CVE-2025-60837 1 Mingsoft 1 Mcms 2026-07-05 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.
CVE-2025-60378 1 Fairsketch 1 Rise Ultimate Project Manager 2026-07-05 N/A 8.1 HIGH
Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDFs, and messaging/chat modules sent to clients or team members, enabling phishing, credential theft, and business email compromise. Automated recurring invoices and messaging amplify the risk by distributing malicious content to multiple recipients.