Vulnerabilities (CVE)

Filtered by CWE-79
Total 47484 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-47098 1 Virtualmin 1 Virtualmin 2026-06-17 N/A 4.8 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability in the Manage Extra Admins under Administration Options in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the real name or description field.
CVE-2023-47097 1 Virtualmin 1 Virtualmin 2026-06-17 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability in the Server Template under System Setting in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Template name field while creating server templates.
CVE-2023-47096 1 Virtualmin 1 Virtualmin 2026-06-17 N/A 5.4 MEDIUM
A Reflected Cross-Site Scripting (XSS) vulnerability in the Cloudmin Services Client under System Setting in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Cloudmin services master field.
CVE-2023-47095 1 Virtualmin 1 Virtualmin 2026-06-17 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability in the Custom fields of Edit Virtual Server under System Customization in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Batch Label field while details of Virtual Server.
CVE-2023-47094 1 Virtualmin 1 Virtualmin 2026-06-17 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability in the Account Plans tab of System Settings in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Plan name field while editing Account plan details.
CVE-2023-47065 1 Adobe 1 Experience Manager 2026-06-17 N/A 5.4 MEDIUM
Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
CVE-2023-47064 1 Adobe 1 Experience Manager 2026-06-17 N/A 5.4 MEDIUM
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
CVE-2023-46998 1 Bootboxjs 1 Bootbox 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), prompt() functions.
CVE-2023-46974 1 Mayurik 1 Courier Management System 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Best Courier Management System v.1.000 allows a remote attacker to execute arbitrary code via a crafted payload to the page parameter in the URL.
CVE-2023-46967 1 Enhancesoft 1 Osticket 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.
CVE-2023-46964 1 Hillstonenet 2 Sc-6000-e3960, Sc-6000-e3960 Firmware 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Hillstone Next Generation FireWall SG-6000-e3960 v.5.5 allows a remote attacker to execute arbitrary code via the use front-end filtering instead of back-end filtering.
CVE-2023-46951 1 Contribsys 1 Sidekiq 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted payload to the uniquejobs function.
CVE-2023-46950 1 Contribsys 1 Sidekiq 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted URL to the filter functions.
CVE-2023-46935 1 Eyoucms 1 Eyoucms 2026-06-17 N/A 5.4 MEDIUM
eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users.
CVE-2023-46925 1 Reportico 1 Reportico 2026-06-17 N/A 4.8 MEDIUM
Reportico 7.1.21 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-46911 1 Jspxcms 1 Jspxcms 2026-06-17 N/A 6.1 MEDIUM
There is a Cross Site Scripting (XSS) vulnerability in the choose_style_tree.do interface of Jspxcms v10.2.0 backend.
CVE-2023-46858 1 Moodle 1 Moodle 2026-06-17 N/A 5.4 MEDIUM
Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."
CVE-2023-46857 1 Squidex.io 1 Squidex 2026-06-17 N/A 5.4 MEDIUM
Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME element. An authenticated attack with assets.create permission is required for exploitation.
CVE-2023-46854 1 Proxmox 1 Proxmox-widget-toolkit 2026-06-17 N/A 5.4 MEDIUM
Proxmox proxmox-widget-toolkit before 4.0.9, as used in multiple Proxmox products, allows XSS via the edit notes feature.
CVE-2023-46824 1 Omaksolutions 1 Slick Popup 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Om Ak Solutions Slick Popup: Contact Form 7 Popup Plugin plugin <= 1.7.14 versions.