Total
47484 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-47098 | 1 Virtualmin | 1 Virtualmin | 2026-06-17 | N/A | 4.8 MEDIUM |
| A Stored Cross-Site Scripting (XSS) vulnerability in the Manage Extra Admins under Administration Options in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the real name or description field. | |||||
| CVE-2023-47097 | 1 Virtualmin | 1 Virtualmin | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Stored Cross-Site Scripting (XSS) vulnerability in the Server Template under System Setting in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Template name field while creating server templates. | |||||
| CVE-2023-47096 | 1 Virtualmin | 1 Virtualmin | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Reflected Cross-Site Scripting (XSS) vulnerability in the Cloudmin Services Client under System Setting in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Cloudmin services master field. | |||||
| CVE-2023-47095 | 1 Virtualmin | 1 Virtualmin | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Stored Cross-Site Scripting (XSS) vulnerability in the Custom fields of Edit Virtual Server under System Customization in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Batch Label field while details of Virtual Server. | |||||
| CVE-2023-47094 | 1 Virtualmin | 1 Virtualmin | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Stored Cross-Site Scripting (XSS) vulnerability in the Account Plans tab of System Settings in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Plan name field while editing Account plan details. | |||||
| CVE-2023-47065 | 1 Adobe | 1 Experience Manager | 2026-06-17 | N/A | 5.4 MEDIUM |
| Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. | |||||
| CVE-2023-47064 | 1 Adobe | 1 Experience Manager | 2026-06-17 | N/A | 5.4 MEDIUM |
| Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | |||||
| CVE-2023-46998 | 1 Bootboxjs | 1 Bootbox | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), prompt() functions. | |||||
| CVE-2023-46974 | 1 Mayurik | 1 Courier Management System | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in Best Courier Management System v.1.000 allows a remote attacker to execute arbitrary code via a crafted payload to the page parameter in the URL. | |||||
| CVE-2023-46967 | 1 Enhancesoft | 1 Osticket | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket. | |||||
| CVE-2023-46964 | 1 Hillstonenet | 2 Sc-6000-e3960, Sc-6000-e3960 Firmware | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Hillstone Next Generation FireWall SG-6000-e3960 v.5.5 allows a remote attacker to execute arbitrary code via the use front-end filtering instead of back-end filtering. | |||||
| CVE-2023-46951 | 1 Contribsys | 1 Sidekiq | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted payload to the uniquejobs function. | |||||
| CVE-2023-46950 | 1 Contribsys | 1 Sidekiq | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted URL to the filter functions. | |||||
| CVE-2023-46935 | 1 Eyoucms | 1 Eyoucms | 2026-06-17 | N/A | 5.4 MEDIUM |
| eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users. | |||||
| CVE-2023-46925 | 1 Reportico | 1 Reportico | 2026-06-17 | N/A | 4.8 MEDIUM |
| Reportico 7.1.21 is vulnerable to Cross Site Scripting (XSS). | |||||
| CVE-2023-46911 | 1 Jspxcms | 1 Jspxcms | 2026-06-17 | N/A | 6.1 MEDIUM |
| There is a Cross Site Scripting (XSS) vulnerability in the choose_style_tree.do interface of Jspxcms v10.2.0 backend. | |||||
| CVE-2023-46858 | 1 Moodle | 1 Moodle | 2026-06-17 | N/A | 5.4 MEDIUM |
| Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not." | |||||
| CVE-2023-46857 | 1 Squidex.io | 1 Squidex | 2026-06-17 | N/A | 5.4 MEDIUM |
| Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME element. An authenticated attack with assets.create permission is required for exploitation. | |||||
| CVE-2023-46854 | 1 Proxmox | 1 Proxmox-widget-toolkit | 2026-06-17 | N/A | 5.4 MEDIUM |
| Proxmox proxmox-widget-toolkit before 4.0.9, as used in multiple Proxmox products, allows XSS via the edit notes feature. | |||||
| CVE-2023-46824 | 1 Omaksolutions | 1 Slick Popup | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Om Ak Solutions Slick Popup: Contact Form 7 Popup Plugin plugin <= 1.7.14 versions. | |||||
