Vulnerabilities (CVE)

Filtered by CWE-79
Total 45311 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-25825 1 Emlog 1 Emlog 2026-07-05 N/A 7.1 HIGH
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Titile in the article category section.
CVE-2025-25823 1 Emlog 1 Emlog 2026-07-05 N/A 7.3 HIGH
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the article header at /admin/article.php.
CVE-2025-25818 1 Emlog 1 Emlog 2026-07-05 N/A 5.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the postStrVar function at article_save.php.
CVE-2025-25612 2026-07-05 N/A 7.1 HIGH
FS Inc S3150-8T2F prior to version S3150-8T2F_2.2.0D_135103 is vulnerable to Cross Site Scripting (XSS) in the Time Range Configuration functionality of the administration interface. An attacker can inject malicious JavaScript into the "Time Range Name" field, which is improperly sanitized. When this input is saved, it is later executed in the browser of any user accessing the affected page, including administrators, resulting in arbitrary script execution in the user's browser.
CVE-2024-57529 1 Jeppesen 1 Jetplanner 2026-07-05 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary code.
CVE-2024-57370 2026-07-05 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain sensitive information via the w parameter.
CVE-2024-57273 1 Netgate 2 Pfsense Ce, Pfsense Plus 2026-07-05 N/A 5.4 MEDIUM
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and a derivable device key generated from the public SSH key.
CVE-2024-57041 1 Nodebb 1 Nodebb 2026-07-05 N/A 4.6 MEDIUM
A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile.
CVE-2024-54998 1 Monicahq 1 Monica 2026-07-05 N/A 5.4 MEDIUM
MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at /people/h:[id]/debts/create.
CVE-2024-54996 1 Monicahq 1 Monica 2026-07-05 N/A 8.8 HIGH
MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and description parameters at /people/ID/reminders/create.
CVE-2024-54994 1 Monicahq 1 Monica 2026-07-05 N/A 6.5 MEDIUM
MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in the Add a new relationship feature.
CVE-2024-53481 1 Phpgurukul 1 Beauty Parlour Management System 2026-07-05 N/A 6.1 MEDIUM
A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "Firstname" and "Last name" parameters.
CVE-2024-53365 1 Phpgurukul 1 Vehicle Parking Management System 2026-07-05 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/profile.php. This vulnerability allows authenticated users to inject malicious XSS scripts into the profile name field.
CVE-2024-52680 1 Eyoucms 1 Eyoucms 2026-07-05 N/A 6.1 MEDIUM
EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn.
CVE-2024-51112 1 Pnetlab 1 Pnetlab 2026-07-05 N/A 6.1 MEDIUM
Open Redirect vulnerability in Pnetlab 5.3.11 allows an attacker to manipulate URLs to redirect users to arbitrary external websites via a crafted script
CVE-2024-51111 1 Pnetlab 1 Pnetlab 2026-07-05 N/A 4.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in Pnetlab 5.3.11 allows an attacker to inject malicious scripts into a web page, which are executed in the context of the victim's browser.
CVE-2024-48417 1 Edimax 2 Br-6476ac, Br-6476ac Firmware 2026-07-05 N/A 5.2 MEDIUM
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Cross Site Scripting (XSS) in : /bin/goahead via /goform/setStaticRoute, /goform/fromSetFilterUrlFilter, and /goform/fromSetFilterClientFilter.
CVE-2024-46606 1 Piwigo 1 Piwigo 2026-07-05 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.
CVE-2024-46605 1 Piwigo 1 Piwigo 2026-07-05 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.
CVE-2024-45932 1 Webkul 1 Krayin Crm 2026-07-05 N/A 4.8 MEDIUM
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2.