Vulnerabilities (CVE)

Filtered by vendor Dovestones Subscribe
Filtered by product Ad Phonebook
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-31013 1 Dovestones 1 Ad Phonebook 2026-04-23 N/A 6.1 MEDIUM
Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Department=HR endpoint. User-supplied input is reflected in the HTTP response without proper input validation or output encoding, allowing execution of arbitrary JavaScript in the victim's browser.