Vulnerabilities (CVE)

Filtered by CWE-79
Total 47492 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-37302 1 Mediawiki 1 Mediawiki 2026-06-17 N/A 6.1 MEDIUM
An issue was discovered in SiteLinksView.php in Wikibase in MediaWiki through 1.39.3. There is XSS via a crafted badge title attribute. This is also related to lack of escaping in wbTemplate (from resources/wikibase/templates.js) for quotes (which can be in a title attribute).
CVE-2023-37299 1 Joplin Project 1 Joplin 2026-06-17 N/A 6.1 MEDIUM
Joplin before 2.11.5 allows XSS via an AREA element of an image map.
CVE-2023-37298 1 Joplin Project 1 Joplin 2026-06-17 N/A 6.1 MEDIUM
Joplin before 2.11.5 allows XSS via a USE element in an SVG document.
CVE-2023-37280 1 Pimcore 1 Admin Classic Bundle 2026-06-17 N/A 5.0 MEDIUM
Pimcore Admin Classic Bundle provides a Backend UI for Pimcore based on the ExtJS framework. An admin who has not setup two factor authentication before is vulnerable for this attack, without need for any form of privilege, causing the application to execute arbitrary scripts/HTML content. This vulnerability has been patched in version 1.0.3.
CVE-2023-37272 1 Sos-berlin 1 Jobscheduler 2026-06-17 N/A 6.3 MEDIUM
JS7 is an Open Source Job Scheduler. Users specify file names when uploading files holding user-generated documentation for JOC Cockpit. Specifically crafted file names allow an XSS attack to inject code that is executed with the browser. Risk of the vulnerability is considered high for branch 1.13 of JobScheduler (JS1). The vulnerability does not affect branch 2.x of JobScheduler (JS7) for releases after 2.1.0. The vulnerability is resolved with release 1.13.19.
CVE-2023-37269 1 Wintercms 1 Winter 2026-06-17 N/A 2.0 LOW
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Users with the `backend.manage_branding` permission can upload SVGs as the application logo. Prior to version 1.2.3, SVG uploads were not sanitized, which could have allowed a stored cross-site scripting (XSS) attack. To exploit the vulnerability, an attacker would already need to have developer or super user level permissions in Winter CMS. This means they would already have extensive access and control within the system. Additionally, to execute the XSS, the attacker would need to convince the victim to directly visit the URL of the maliciously uploaded SVG, and the application would have to be using local storage where uploaded files are served under the same domain as the application itself instead of a CDN. This is because all SVGs in Winter CMS are rendered through an `img` tag, which prevents any payloads from being executed directly. These two factors significantly limit the potential harm of this vulnerability. This issue has been patched in v1.2.3 through the inclusion of full support for SVG uploads and automatic sanitization of uploaded SVG files. As a workaround, one may apply the patches manually.
CVE-2023-37259 1 Matrix-react-sdk Project 1 Matrix-react-sdk 2026-06-17 N/A 6.1 MEDIUM
matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. The Export Chat feature includes certain attacker-controlled elements in the generated document without sufficient escaping, leading to stored Cross site scripting (XSS). Since the Export Chat feature generates a separate document, an attacker can only inject code run from the `null` origin, restricting the impact. However, the attacker can still potentially use the XSS to leak message contents. A malicious homeserver is a potential attacker since the affected inputs are controllable server-side. This issue has been addressed in commit `22fcd34c60` which is included in release version 3.76.0. Users are advised to upgrade. The only known workaround for this issue is to disable or to not use the Export Chat feature.
CVE-2023-37257 1 Dataease 1 Dataease 2026-06-17 N/A 5.4 MEDIUM
DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, the DataEase panel and dataset have a stored cross-site scripting vulnerability. The vulnerability has been fixed in v1.18.9. There are no known workarounds.
CVE-2023-37256 1 Mediawiki 1 Mediawiki 2026-06-17 N/A 6.1 MEDIUM
An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. It allows one to store javascript: URLs in URL fields, and automatically links these URLs.
CVE-2023-37255 1 Mediawiki 1 Mediawiki 2026-06-17 N/A 6.1 MEDIUM
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In Special:CheckUser, a check of the "get edits" type is vulnerable to HTML injection through the User-Agent HTTP request header.
CVE-2023-37254 1 Mediawiki 1 Mediawiki 2026-06-17 N/A 6.1 MEDIUM
An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. XSS can occur in Special:CargoQuery via a crafted page item when using the default format.
CVE-2023-37251 1 Mediawiki 1 Mediawiki 2026-06-17 N/A 6.1 MEDIUM
An issue was discovered in the GoogleAnalyticsMetrics extension for MediaWiki through 1.39.3. The googleanalyticstrackurl parser function does not properly escape JavaScript in the onclick handler and does not prevent use of javascript: URLs.
CVE-2023-37225 1 Pexip 1 Pexip Infinity 2026-06-17 N/A 6.1 MEDIUM
Pexip Infinity before 32 allows Webapp1 XSS via preconfigured links.
CVE-2023-37223 1 Archerirm 1 Archer 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows a remote authenticated attacker to execute arbitrary code via a crafted malicious script.
CVE-2023-37222 1 Farsight 1 Provide Server 2026-06-17 N/A 4.8 MEDIUM
Farsight Tech Nordic AB ProVide version 14.5 - Multiple XSS vulnerabilities (CWE-79) can be exploited by a user with administrator privilege.
CVE-2023-37221 1 7-twenty 1 Bot 2026-06-17 N/A 8.8 HIGH
7Twenty BOT - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
CVE-2023-37191 1 Issabel 1 Pbx 2026-06-17 N/A 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Group and Description parameters.
CVE-2023-37190 1 Issabel 1 Pbx 2026-06-17 N/A 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Virtual Fax Name and Caller ID Name parameters under the New Virtual Fax feature.
CVE-2023-37189 1 Issabel 1 Pbx 2026-06-17 N/A 4.8 MEDIUM
A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Name or Prefix fields under the Create New Rate module.
CVE-2023-37164 1 Diafan 1 Diafan.cms 2026-06-17 N/A 6.1 MEDIUM
Diafan CMS v6.0 was discovered to contain a reflected cross-site scripting via the cat_id parameter at /shop/?module=shop&action=search.