Vulnerabilities (CVE)

Filtered by CWE-79
Total 47486 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-44089 1 Pandorafms 1 Pandora Fms 2026-06-17 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). It was possible to execute malicious JS code on Visual Consoles. This issue affects Pandora FMS: from 700 through 774.
CVE-2023-44075 1 Small Crm Project 1 Small Crm 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Small CRM in PHP v.3.0 allows a remote attacker to execute arbitrary code via a crafted payload to the Address parameter.
CVE-2023-44048 1 Oretnom23 1 Expense Tracker 2026-06-17 N/A 5.4 MEDIUM
Sourcecodester Expense Tracker App v1 is vulnerable to Cross Site Scripting (XSS) via add category.
CVE-2023-44043 1 Blackcat-cms 1 Blackcat Cms 2026-06-17 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in /install/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website title parameter.
CVE-2023-44042 1 Blackcat-cms 1 Blackcat Cms 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in /settings/index.php of Black Cat CMS 1.4.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website header parameter.
CVE-2023-44040 1 Veridiumid 1 Veridiumad 2026-06-17 N/A 6.1 MEDIUM
In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker for JavaScript execution in the context of the user trying to authenticate.
CVE-2023-44012 1 Mojoportal 1 Mojoportal 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the helpkey parameter in the Help.aspx component.
CVE-2023-43999 1 Linecorp 1 Line 2026-06-17 N/A 5.4 MEDIUM
An issue in COLORFUL_laundry mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
CVE-2023-43988 1 Linecorp 1 Line 2026-06-17 N/A 5.4 MEDIUM
An issue in nature fitness saijo mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
CVE-2023-43971 1 Lizhipay 1 Acg-faka 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in ACG-faka v1.1.7 allows a remote attacker to execute arbitrary code via the encode parameter in Index.php.
CVE-2023-43962 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability in Xunrui CMS Public Edition v.4.6.1 allows a remote attacker to execute arbitrary code via the project name function in the project settings tab.
CVE-2023-43953 1 Sscms 1 Sscms 2026-06-17 N/A 5.4 MEDIUM
SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.
CVE-2023-43952 1 Sscms Project 1 Sscms 2026-06-17 N/A 5.4 MEDIUM
SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management component.
CVE-2023-43951 1 Sscms Project 1 Sscms 2026-06-17 N/A 5.4 MEDIUM
SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Column Management component.
CVE-2023-43944 1 Oretnom23 1 Task Management System 2026-06-17 N/A 5.4 MEDIUM
A Stored Cross Site Scripting (XSS) vulnerability was found in SourceCodester Task Management System 1.0. It allows attackers to execute arbitrary code via parameter field in index.php?page=project_list.
CVE-2023-43906 1 Onworks 1 Xolo Cms 2026-06-17 N/A 6.1 MEDIUM
Xolo CMS v0.11 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.
CVE-2023-43884 1 Intelliants 1 Subrion 2026-06-17 N/A 5.4 MEDIUM
A Cross-site scripting (XSS) vulnerability in Reference ID from the panel Transactions, of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Reference ID' parameter.
CVE-2023-43879 1 Ritecms 1 Ritecms 2026-06-17 N/A 4.8 MEDIUM
Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the Global Content Blocks in the Administration Menu.
CVE-2023-43878 1 Ritecms 1 Ritecms 2026-06-17 N/A 5.4 MEDIUM
Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload into the Main Menu Items in the Administration Menu.
CVE-2023-43877 1 Ritecms 1 Ritecms 2026-06-17 N/A 4.8 MEDIUM
Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a payload crafted in the Home Page fields in the Administration menu.