Vulnerabilities (CVE)

Filtered by CWE-79
Total 47484 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-47662 1 Goldbroker 1 Live Gold Price \& Silver Price Charts Widgets 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GoldBroker.Com Live Gold Price & Silver Price Charts Widgets plugin <= 2.4 versions.
CVE-2023-47660 1 Wpwham 1 Product Visibility By Country For Woocommerce 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Wham Product Visibility by Country for WooCommerce plugin <= 1.4.9 versions.
CVE-2023-47659 1 Lava-code 1 Lava Directory Manager 2026-06-17 N/A 6.5 MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <= 1.1.34 versions.
CVE-2023-47658 1 Actpro 1 Extra Product Options For Woocommerce 2026-06-17 N/A 5.9 MEDIUM
Auth. (ShopManager+) Stored Cross-Site Scripting (XSS) vulnerability in actpro Extra Product Options for WooCommerce plugin <= 3.0.3 versions.
CVE-2023-47657 1 Grandplugins 1 Woo Quick View And Buy Now 2026-06-17 N/A 5.9 MEDIUM
Auth. (ShopManager+) Stored Cross-Site Scripting (XSS) vulnerability in GrandPlugins Direct Checkout – Quick View – Buy Now For WooCommerce plugin <= 1.5.8 versions.
CVE-2023-47656 1 Marcomilesi 1 Anac Xml Bandi Di Gara 2026-06-17 N/A 5.9 MEDIUM
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi ANAC XML Bandi di Gara plugin <= 7.5 versions.
CVE-2023-47654 1 Livescore 1 Bzscore 2026-06-17 N/A 6.5 MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in livescore.Bz BZScore – Live Score plugin <= 1.03 versions.
CVE-2023-47653 1 Theweb-designs 1 Twb Woocommerce 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Abu Bakar TWB Woocommerce Reviews plugin <= 1.7.5 versions.
CVE-2023-47646 1 Cedcommerce 1 Recently Viewed And Most Viewed Products 2026-06-17 N/A 5.9 MEDIUM
Auth. (Shop Manager+) Stored Cross-Site Scripting (XSS) vulnerability in CedCommerce Recently viewed and most viewed products plugin <= 1.1.1 versions.
CVE-2023-47626 1 Combodo 1 Itop 2026-06-17 N/A 8.8 HIGH
iTop is an IT service management platform. When displaying/editing the user's personal tokens, XSS attacks are possible. This vulnerability is fixed in 3.1.1.
CVE-2023-47623 1 Clockworkmod 1 Scrypted 2026-06-17 N/A 6.1 MEDIUM
Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior, a reflected cross-site scripting vulnerability exists in the login page via the `redirect_uri` parameter. By specifying a url with the javascript scheme (`javascript:`), an attacker can run arbitrary JavaScript code after the login.
CVE-2023-47622 1 Combodo 1 Itop 2026-06-17 N/A 8.8 HIGH
iTop is an IT service management platform. When dashlet are refreshed, XSS attacks are possible. This vulnerability is fixed in 3.0.4 and 3.1.1.
CVE-2023-47620 1 Clockworkmod 1 Scrypted 2026-06-17 N/A 6.1 MEDIUM
Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior, a reflected cross-site scripting vulnerability exists in the plugin-http.ts file via the `owner' and 'pkg` parameters. An attacker can run arbitrary JavaScript code.
CVE-2023-47575 1 Relyum 4 Rely-pcie, Rely-pcie Firmware, Rely-rec and 1 more 2026-06-17 N/A 6.1 MEDIUM
An issue was discovered on Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices. The web interfaces of the Relyum devices are susceptible to reflected XSS.
CVE-2023-47561 1 Qnap 1 Photo Station 2026-06-17 N/A 5.5 MEDIUM
A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later
CVE-2023-47559 1 Qnap 1 Qumagie 2026-06-17 N/A 5.5 MEDIUM
A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: QuMagie 2.2.1 and later
CVE-2023-47554 1 Denk 1 Actueel Financieel Nieuws 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DenK BV Actueel Financieel Nieuws – Denk Internet Solutions plugin <= 5.1.0 versions.
CVE-2023-47549 1 Spider-themes 1 Eazydocs 2026-06-17 N/A 6.8 MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability on 302 response page in spider-themes EazyDocs plugin <= 2.3.3 versions.
CVE-2023-47547 1 Wpfactory 1 Products\, Order \& Customers Export For Woocommerce 2026-06-17 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory Products, Order & Customers Export for WooCommerce plugin <= 2.0.7 versions.
CVE-2023-47546 1 Walterpinem 1 Oneclick Chat To Order 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Walter Pinem OneClick Chat to Order plugin <= 1.0.4.2 versions.