Vulnerabilities (CVE)

Filtered by CWE-79
Total 47493 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-36309 1 Phpjabbers 1 Document Creator 2026-06-17 N/A 6.1 MEDIUM
There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Document Creator v1.0.
CVE-2023-36306 1 Adiscon 1 Loganalyzer 2026-06-17 N/A 6.1 MEDIUM
A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php components.
CVE-2023-36291 1 Maxsite 1 Maxsite Cms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_content parameter in the admin/page_new file.
CVE-2023-36289 1 Webkul 1 Qloapps 2026-06-17 N/A 6.1 MEDIUM
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.
CVE-2023-36288 1 Webkul 1 Qloapps 2026-06-17 N/A 5.4 MEDIUM
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter.
CVE-2023-36287 1 Webkul 1 Qloapps 2026-06-17 N/A 6.1 MEDIUM
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST controller parameter.
CVE-2023-36259 1 Craftcms 1 Craft Cms 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation.
CVE-2023-36236 1 Webkul 1 Bagisto 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.
CVE-2023-36234 1 Netbox 1 Netbox 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in Netbox 3.5.1, allows attackers to execute arbitrary code via Name field in device-roles/add function.
CVE-2023-36217 1 Xoops 1 Xoops 2026-06-17 N/A 9.0 CRITICAL
Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.
CVE-2023-36211 1 Cubiclesoft 1 Barebones Cms 2026-06-17 N/A 5.4 MEDIUM
The Barebones CMS v2.0.2 is vulnerable to Stored Cross-Site Scripting (XSS) when an authenticated user interacts with certain features on the admin panel.
CVE-2023-36163 1 Buildagate Project 1 Buildagate 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the mc parameter of the URL.
CVE-2023-36138 1 Phpjabbers 1 Cleaning Business Software 2026-06-17 N/A 6.1 MEDIUM
PHPJabbers Cleaning Business Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the theme parameter of preview.php.
CVE-2023-36137 1 Phpjabbers 1 Class Scheduling System 2026-06-17 N/A 6.1 MEDIUM
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduling System 1.0.
CVE-2023-36126 1 Phpjabbers 1 Appointment Scheduler 2026-06-17 N/A 6.1 MEDIUM
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Appointment Scheduler v3.0
CVE-2023-36121 1 E107 1 E107 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the description function in the SEO project.
CVE-2023-36118 1 Faculty Evaluation System Project 1 Faculty Evaluation System 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Faculty Evaulation System using PHP/MySQLi v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the page parameter.
CVE-2023-36093 1 Eyoucms 1 Eyoucms 2026-06-17 N/A 5.4 MEDIUM
There is a storage type cross site scripting (XSS) vulnerability in the filing number of the Basic Information tab on the backend management page of EyouCMS v1.6.3
CVE-2023-36031 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 7.6 HIGH
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-36030 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 6.1 MEDIUM
Microsoft Dynamics 365 Sales Spoofing Vulnerability