Vulnerabilities (CVE)

Filtered by CWE-79
Total 47486 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-43876 1 Octobercms 1 October 2026-06-17 N/A 5.4 MEDIUM
A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost field.
CVE-2023-43875 1 Intelliants 1 Subrion Cms 2026-06-17 N/A 6.1 MEDIUM
Multiple Cross-Site Scripting (XSS) vulnerabilities in installation of Subrion CMS v.4.2.1 allows a local attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost, dbname, dbuser, adminusername and adminemail.
CVE-2023-43874 1 E107 1 E107 Cms 2026-06-17 N/A 5.4 MEDIUM
Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Copyright and Author fields in the Meta & Custom Tags Menu.
CVE-2023-43873 1 E107 1 E107 Cms 2026-06-17 N/A 5.4 MEDIUM
A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Name filed in the Manage Menu.
CVE-2023-43872 1 Cmsmadesimple 1 Cms Made Simple 2026-06-17 N/A 5.4 MEDIUM
A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).
CVE-2023-43871 1 Wbce 1 Wbce Cms 2026-06-17 N/A 5.4 MEDIUM
A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).
CVE-2023-43857 1 Iteachyou 1 Dreamer Cms 2026-06-17 N/A 5.4 MEDIUM
Dreamer CMS v4.1.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /admin/u/toIndex.
CVE-2023-43830 1 Intelliants 1 Subrion 2026-06-17 N/A 5.4 MEDIUM
A Cross-site scripting (XSS) vulnerability in /panel/configuration/financial/ of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into several fields: 'Minimum deposit', 'Maximum deposit' and/or 'Maximum balance'.
CVE-2023-43828 1 Intelliants 1 Subrion 2026-06-17 N/A 5.4 MEDIUM
A Cross-site scripting (XSS) vulnerability in /panel/languages/ of Subrion v4.2.1 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Title' parameter.
CVE-2023-43797 1 Bigbluebutton 1 Bigbluebutton 2026-06-17 N/A 6.3 MEDIUM
BigBlueButton is an open-source virtual classroom. Prior to versions 2.6.11 and 2.7.0-beta.3, Guest Lobby was vulnerable to cross-site scripting when users wait to enter the meeting due to inserting unsanitized messages to the element using unsafe innerHTML. Text sanitizing was added for lobby messages starting in versions 2.6.11 and 2.7.0-beta.3. There are no known workarounds.
CVE-2023-43790 1 Combodo 1 Itop 2026-06-17 N/A 5.7 MEDIUM
iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object friendlyname value. This vulnerability is fixed in 3.1.1 and 3.2.0.
CVE-2023-43770 2 Debian, Roundcube 2 Debian Linux, Webmail 2026-06-17 N/A 6.1 MEDIUM
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
CVE-2023-43763 1 Withsecure 1 F-secure Policy Manager 2026-06-17 N/A 6.1 MEDIUM
Certain WithSecure products allow XSS via an unvalidated parameter in the endpoint. This affects WithSecure Policy Manager 15 on Windows and Linux.
CVE-2023-43735 1 Oscommerce 1 Oscommerce 2026-06-17 N/A 5.4 MEDIUM
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "formats_titles[7]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
CVE-2023-43734 1 Oscommerce 1 Oscommerce 2026-06-17 N/A 5.4 MEDIUM
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
CVE-2023-43733 1 Oscommerce 1 Oscommerce 2026-06-17 N/A 5.4 MEDIUM
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "company_address" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
CVE-2023-43732 1 Oscommerce 1 Oscommerce 2026-06-17 N/A 5.4 MEDIUM
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tax_class_title" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
CVE-2023-43731 1 Oscommerce 1 Oscommerce 2026-06-17 N/A 5.4 MEDIUM
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "zone_name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
CVE-2023-43730 1 Oscommerce 1 Oscommerce 2026-06-17 N/A 5.4 MEDIUM
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "countries_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
CVE-2023-43729 1 Oscommerce 1 Oscommerce 2026-06-17 N/A 5.4 MEDIUM
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "xsell_type_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.