Vulnerabilities (CVE)

Filtered by CWE-79
Total 47486 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-41107 1 Tef 1 Tef Portal 2026-06-17 N/A 5.4 MEDIUM
TEF portal 2023-07-17 is vulnerable to a persistent cross site scripting (XSS)attack.
CVE-2023-41103 1 Interactsoftware 1 Interact 2026-06-17 N/A 5.4 MEDIUM
Interact 7.9.79.5 allows stored Cross-site Scripting (XSS) attacks in several locations, allowing an attacker to store a JavaScript payload.
CVE-2023-41049 1 Decentraland 1 Single Sign On Client 2026-06-17 N/A 7.5 HIGH
@dcl/single-sign-on-client is an open source npm library which deals with single sign on authentication flows. Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javascript:` prefix. This vulnerability has been patched on version `0.1.0`. Users are advised to upgrade. Users unable to upgrade should limit untrusted user input to the `init` function.
CVE-2023-41048 1 Plone 2 Namedfile, Plone 2026-06-17 N/A 3.7 LOW
plone.namedfile allows users to handle `File` and `Image` fields targeting, but not depending on, Plone Dexterity content. Prior to versions 5.6.1, 6.0.3, 6.1.3, and 6.2.1, there is a stored cross site scripting vulnerability for SVG images. A security hotfix from 2021 already partially fixed this by making sure SVG images are always downloaded instead of shown inline. But the same problem still exists for scales of SVG images. Note that an image tag with an SVG image as source is not vulnerable, even when the SVG image contains malicious code. To exploit the vulnerability, an attacker would first need to upload an image, and then trick a user into following a specially crafted link. Patches are available in versions 5.6.1 (for Plone 5.2), 6.0.3 (for Plone 6.0.0-6.0.4), 6.1.3 (for Plone 6.0.5-6.0.6), and 6.2.1 (for Plone 6.0.7). There are no known workarounds.
CVE-2023-40877 1 Dedecms 1 Dedecms 2026-06-17 N/A 5.4 MEDIUM
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_edit.php via the title parameter.
CVE-2023-40876 1 Dedecms 1 Dedecms 2026-06-17 N/A 5.4 MEDIUM
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title parameter.
CVE-2023-40875 1 Dedecms 1 Dedecms 2026-06-17 N/A 5.4 MEDIUM
DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_edit.php via the votename and votenote parameters.
CVE-2023-40874 1 Dedecms 1 Dedecms 2026-06-17 N/A 5.4 MEDIUM
DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_add.php via the votename and voteitem1 parameters.
CVE-2023-40869 1 Moosocial 1 Moosocial 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in mooSocial mooSocial Software 3.1.6 and 3.1.7 allows a remote attacker to execute arbitrary code via a crafted script to the edit_menu, copuon, and group_categorias functions.
CVE-2023-40851 1 User Registration \& Login And User Management System With Admin Panel Project 1 User Registration \& Login And User Management System With Admin Panel 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in Phpgurukul User Registration & Login and User Management System With admin panel 3.0 allows attackers to run arbitrary code via fname, lname, email, and contact fields of the user registration page.
CVE-2023-40819 1 Devlop.systems 1 Id4portais 2026-06-17 N/A 6.1 MEDIUM
ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injection vulnerability.
CVE-2023-40817 1 Opencrx 1 Opencrx 2026-06-17 N/A 6.1 MEDIUM
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Product Configuration Name Field.
CVE-2023-40816 1 Opencrx 1 Opencrx 2026-06-17 N/A 6.1 MEDIUM
OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Milestone Name Field.
CVE-2023-40815 1 Opencrx 1 Opencrx 2026-06-17 N/A 6.1 MEDIUM
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Category Creation Name Field.
CVE-2023-40814 1 Opencrx 1 Opencrx 2026-06-17 N/A 6.1 MEDIUM
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Name Field.
CVE-2023-40813 1 Opencrx 1 Opencrx 2026-06-17 N/A 6.1 MEDIUM
OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Saved Search Creation.
CVE-2023-40812 1 Opencrx 1 Opencrx 2026-06-17 N/A 6.1 MEDIUM
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Group Name Field.
CVE-2023-40810 1 Opencrx 1 Opencrx 2026-06-17 N/A 6.1 MEDIUM
OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field.
CVE-2023-40809 1 Opencrx 1 Opencrx 2026-06-17 N/A 6.1 MEDIUM
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number.
CVE-2023-40786 1 Hkcms 1 Hkcms 2026-06-17 N/A 5.4 MEDIUM
HKcms v2.3.0.230709 is vulnerable to Cross Site Scripting (XSS) allowing administrator cookies to be stolen.