Total
47486 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-41107 | 1 Tef | 1 Tef Portal | 2026-06-17 | N/A | 5.4 MEDIUM |
| TEF portal 2023-07-17 is vulnerable to a persistent cross site scripting (XSS)attack. | |||||
| CVE-2023-41103 | 1 Interactsoftware | 1 Interact | 2026-06-17 | N/A | 5.4 MEDIUM |
| Interact 7.9.79.5 allows stored Cross-site Scripting (XSS) attacks in several locations, allowing an attacker to store a JavaScript payload. | |||||
| CVE-2023-41049 | 1 Decentraland | 1 Single Sign On Client | 2026-06-17 | N/A | 7.5 HIGH |
| @dcl/single-sign-on-client is an open source npm library which deals with single sign on authentication flows. Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javascript:` prefix. This vulnerability has been patched on version `0.1.0`. Users are advised to upgrade. Users unable to upgrade should limit untrusted user input to the `init` function. | |||||
| CVE-2023-41048 | 1 Plone | 2 Namedfile, Plone | 2026-06-17 | N/A | 3.7 LOW |
| plone.namedfile allows users to handle `File` and `Image` fields targeting, but not depending on, Plone Dexterity content. Prior to versions 5.6.1, 6.0.3, 6.1.3, and 6.2.1, there is a stored cross site scripting vulnerability for SVG images. A security hotfix from 2021 already partially fixed this by making sure SVG images are always downloaded instead of shown inline. But the same problem still exists for scales of SVG images. Note that an image tag with an SVG image as source is not vulnerable, even when the SVG image contains malicious code. To exploit the vulnerability, an attacker would first need to upload an image, and then trick a user into following a specially crafted link. Patches are available in versions 5.6.1 (for Plone 5.2), 6.0.3 (for Plone 6.0.0-6.0.4), 6.1.3 (for Plone 6.0.5-6.0.6), and 6.2.1 (for Plone 6.0.7). There are no known workarounds. | |||||
| CVE-2023-40877 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 5.4 MEDIUM |
| DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_edit.php via the title parameter. | |||||
| CVE-2023-40876 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 5.4 MEDIUM |
| DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title parameter. | |||||
| CVE-2023-40875 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 5.4 MEDIUM |
| DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_edit.php via the votename and votenote parameters. | |||||
| CVE-2023-40874 | 1 Dedecms | 1 Dedecms | 2026-06-17 | N/A | 5.4 MEDIUM |
| DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_add.php via the votename and voteitem1 parameters. | |||||
| CVE-2023-40869 | 1 Moosocial | 1 Moosocial | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in mooSocial mooSocial Software 3.1.6 and 3.1.7 allows a remote attacker to execute arbitrary code via a crafted script to the edit_menu, copuon, and group_categorias functions. | |||||
| CVE-2023-40851 | 1 User Registration \& Login And User Management System With Admin Panel Project | 1 User Registration \& Login And User Management System With Admin Panel | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to run arbitrary code via fname, lname, email, and contact fields of the user registration page. | |||||
| CVE-2023-40819 | 1 Devlop.systems | 1 Id4portais | 2026-06-17 | N/A | 6.1 MEDIUM |
| ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injection vulnerability. | |||||
| CVE-2023-40817 | 1 Opencrx | 1 Opencrx | 2026-06-17 | N/A | 6.1 MEDIUM |
| OpenCRX version 5.2.0 is vulnerable to HTML injection via the Product Configuration Name Field. | |||||
| CVE-2023-40816 | 1 Opencrx | 1 Opencrx | 2026-06-17 | N/A | 6.1 MEDIUM |
| OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Milestone Name Field. | |||||
| CVE-2023-40815 | 1 Opencrx | 1 Opencrx | 2026-06-17 | N/A | 6.1 MEDIUM |
| OpenCRX version 5.2.0 is vulnerable to HTML injection via the Category Creation Name Field. | |||||
| CVE-2023-40814 | 1 Opencrx | 1 Opencrx | 2026-06-17 | N/A | 6.1 MEDIUM |
| OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Name Field. | |||||
| CVE-2023-40813 | 1 Opencrx | 1 Opencrx | 2026-06-17 | N/A | 6.1 MEDIUM |
| OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Saved Search Creation. | |||||
| CVE-2023-40812 | 1 Opencrx | 1 Opencrx | 2026-06-17 | N/A | 6.1 MEDIUM |
| OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Group Name Field. | |||||
| CVE-2023-40810 | 1 Opencrx | 1 Opencrx | 2026-06-17 | N/A | 6.1 MEDIUM |
| OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field. | |||||
| CVE-2023-40809 | 1 Opencrx | 1 Opencrx | 2026-06-17 | N/A | 6.1 MEDIUM |
| OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number. | |||||
| CVE-2023-40786 | 1 Hkcms | 1 Hkcms | 2026-06-17 | N/A | 5.4 MEDIUM |
| HKcms v2.3.0.230709 is vulnerable to Cross Site Scripting (XSS) allowing administrator cookies to be stolen. | |||||
