Vulnerabilities (CVE)

Filtered by CWE-79
Total 47486 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-40659 1 Joomboost 1 Easy Quick Contact 2026-06-17 N/A 6.1 MEDIUM
A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla.
CVE-2023-40658 1 Deconf 1 Clicky Analytics Dashboard 2026-06-17 N/A 6.1 MEDIUM
A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla.
CVE-2023-40657 1 Artio 1 Joomdoc 2026-06-17 N/A 6.1 MEDIUM
A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla.
CVE-2023-40656 1 Plasma-web 1 Quickform 2026-06-17 N/A 6.1 MEDIUM
A reflected XSS vulnerability was discovered in the Quickform component for Joomla.
CVE-2023-40655 1 Mooj 1 Proforms 2026-06-17 N/A 6.1 MEDIUM
A reflected XSS vulnerability was discovered in the Proforms Basic component for Joomla.
CVE-2023-40628 1 Extplorer 1 Extplorer 2026-06-17 N/A 6.1 MEDIUM
A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.
CVE-2023-40627 1 Mlwebtechnologies 1 Livingword 2026-06-17 N/A 6.1 MEDIUM
A reflected XSS vulnerability was discovered in the LivingWord component for Joomla.
CVE-2023-40624 1 Sap 1 Netweaver Application Server Abap 2026-06-17 N/A 5.5 MEDIUM
SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 702, SAP_BASIS 731, allows an attacker to inject JavaScript code that can be executed in the web-application. An attacker could thereby control the behavior of this web-application.
CVE-2023-40618 1 Openknowledgemaps 1 Head Start 2026-06-17 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start versions 4, 5, 6, 7 as well as Visual Project Explorer 1.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'service' parameter in 'headstart_snapshot.php'.
CVE-2023-40617 1 Openknowledgemaps 1 Head Start 2026-06-17 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start 7 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'file' parameter in 'displayPDF.php'.
CVE-2023-40605 1 93digital 1 Typing Effect 2026-06-17 N/A 6.5 MEDIUM
Auth. (contributor) Cross-Site Scripting (XSS) vulnerability in 93digital Typing Effect plugin <= 1.3.6 versions.
CVE-2023-40604 1 Jesmadsen 1 Cookies By Jm 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jes Madsen Cookies by JM plugin <= 1.0 versions.
CVE-2023-40601 1 Estatik 1 Estatik Mortgage Calculator 2026-06-17 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versions.
CVE-2023-40592 1 Splunk 2 Splunk, Splunk Cloud Platform 2026-06-17 N/A 8.4 HIGH
In Splunk Enterprise versions below 9.1.1, 9.0.6, and 8.2.12, an attacker can craft a special web request that can result in reflected cross-site scripting (XSS) on the “/app/search/table” web endpoint. Exploitation of this vulnerability can lead to the execution of arbitrary commands on the Splunk platform instance.
CVE-2023-40577 2 Debian, Prometheus 2 Debian Linux, Alertmanager 2026-06-17 N/A 7.5 HIGH
Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue has been fixed in Alertmanager version 0.2.51.
CVE-2023-40560 1 Toolstack 1 Schedule Posts Calendar 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Greg Ross Schedule Posts Calendar plugin <= 5.2 versions.
CVE-2023-40554 1 Adenion 1 Blog2social 2026-06-17 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blog2Social, Adenion Blog2Social: Social Media Auto Post & Scheduler plugin <= 7.2.0 versions.
CVE-2023-40553 1 Plausible 1 Plausible Analytics 2026-06-17 N/A 5.8 MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Plausible.Io Plausible Analytics plugin <= 1.3.3 versions.
CVE-2023-40552 1 Codeinitiator 1 Fitness Calculators Plugin 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gurcharan Singh Fitness calculators plugin plugin <= 2.0.7 versions.
CVE-2023-40535 1 I-pro 1 Video Insight 2026-06-17 N/A 5.4 MEDIUM
Stored cross-site scripting vulnerability in View setting page of VI Web Client prior to 7.9.6 allows a remote authenticated attacker to inject an arbitrary script.