Vulnerabilities (CVE)

Filtered by CWE-79
Total 47493 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-36970 1 Cmsmadesimple 1 Cms Made Simple 2026-06-17 N/A 5.4 MEDIUM
A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.
CVE-2023-36942 1 Phpgurukul 1 Online Fire Reporting System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the website title field.
CVE-2023-36941 1 Phpgurukul 1 Online Fire Reporting System 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the team name, leader, and member fields.
CVE-2023-36940 1 Phpgurukul 1 Online Fire Reporting System 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field.
CVE-2023-36939 1 Phpgurukul 1 Hostel Management System 2026-06-17 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the search booking field.
CVE-2023-36936 1 Phpgurukul 1 Online Security Guards Hiring System 2026-06-17 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in PHPGurukul Online Security Guards Hiring System using PHP and MySQL 1.0 allows attackers to execute arbitrary code via a crafted payload to the search booking box.
CVE-2023-36918 1 Sap 1 Enable Now 2026-06-17 N/A 6.1 MEDIUM
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-Content-Type-Options response header is not implemented, allowing an unauthenticated attacker to trigger MIME type sniffing, which leads to Cross-Site Scripting, which could result in disclosure or modification of information.
CVE-2023-36892 1 Microsoft 1 Sharepoint Server 2026-06-17 N/A 8.0 HIGH
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2023-36891 1 Microsoft 1 Sharepoint Server 2026-06-17 N/A 8.0 HIGH
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2023-36886 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 7.6 HIGH
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-36828 1 Statamic 1 Statamic 2026-06-17 N/A 5.5 MEDIUM
Statamic is a flat-first, Laravel and Git powered content management system. Prior to version 4.10.0, the SVG tag does not sanitize malicious SVG. Therefore, an attacker can exploit this vulnerability to perform cross-site scripting attacks using SVG, even when using the `sanitize` function. Version 4.10.0 contains a patch for this issue.
CVE-2023-36823 2 Debian, Sanitize Project 2 Debian Linux, Sanitize 2026-06-17 N/A 7.1 HIGH
Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize starting with version 3.0.0 and prior to version 6.0.2 when Sanitize is configured to use the built-in "relaxed" config or when using a custom config that allows `style` elements and one or more CSS at-rules. This could result in cross-site scripting or other undesired behavior when the malicious HTML and CSS are rendered in a browser. Sanitize 6.0.2 performs additional escaping of CSS in `style` element content, which fixes this issue. Users who are unable to upgrade can prevent this issue by using a Sanitize config that doesn't allow `style` elements, using a Sanitize config that doesn't allow CSS at-rules, or by manually escaping the character sequence `</` as `<\/` in `style` element content.
CVE-2023-36816 1 2fauth 1 2fauth 2026-06-17 N/A 6.1 MEDIUM
2FA is a Web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Cross site scripting (XSS) injection can be done via the account/service field. This was tested in docker-compose environment. This vulnerability has been patched in version 4.0.3.
CVE-2023-36809 1 Kiwitcms 1 Kiwi Tcms 2026-06-17 N/A 8.1 HIGH
Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12.5 had introduced changes which were meant to serve all uploaded files as plain text in order to prevent browsers from executing potentially dangerous files when such files are accessed directly. The previous Nginx configuration was incorrect allowing certain browsers like Firefox to ignore the `Content-Type: text/plain` header on some occasions thus allowing potentially dangerous scripts to be executed. Additionally, file upload validators and parts of the HTML rendering code had been found to require additional sanitation and improvements. Version 12.5 fixes this vulnerability with updated Nginx content type configuration, improved file upload validation code to prevent more potentially dangerous uploads, and Sanitization of test plan names used in the `tree_view_html()` function.
CVE-2023-36806 1 Contao 1 Contao 2026-06-17 N/A 6.5 MEDIUM
Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and 5.1.10, it is possible for untrusted backend users to inject malicious code into headline fields in the back end, which will be executed both in the element preview (back end) and on the website (front end). Installations are only affected if there are untrusted back end users who have the rights to modify headline fields, or other fields using the input unit widget. Contao 4.9.42, 4.13.28, and 5.1.10 have a patch for this issue. As a workaround, disable the login for all untrusted back end users.
CVE-2023-36800 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 7.6 HIGH
Dynamics Finance and Operations Cross-site Scripting Vulnerability
CVE-2023-36692 1 Wp-cirrus Project 1 Wp-cirrus 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christian Kramer & Hendrik Thole WP-Cirrus plugin <= 0.6.11 versions.
CVE-2023-36689 1 Wpfactory 1 Wpfactory Helper 2026-06-17 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory WPFactory Helper plugin <= 1.5.2 versions.
CVE-2023-36688 1 Idoweb 1 Simple Site Verify 2026-06-17 N/A 4.3 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Mann Simple Site Verify plugin <= 1.0.7 versions.
CVE-2023-36686 1 Cartflows 1 Cartflows 2026-06-17 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CartFlows Pro plugin <= 1.11.11 versions.