Total
47493 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-34666 | 1 Phpgurukul | 1 Cyber Cafe Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in Phpgurukul Cyber Cafe Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the admin username parameter. | |||||
| CVE-2023-34657 | 1 Eyoucms | 1 Eyoucms | 2026-06-17 | N/A | 4.8 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in Eyoucms v1.6.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the web_recordnum parameter. | |||||
| CVE-2023-34654 | 1 Taogogo | 1 Taocms | 2026-06-17 | N/A | 6.1 MEDIUM |
| taocms <=3.0.2 is vulnerable to Cross Site Scripting (XSS). | |||||
| CVE-2023-34652 | 1 Phpgurukul | 1 Hostel Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course. | |||||
| CVE-2023-34651 | 1 Hospital Management System Project | 1 Hospital Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| PHPgurukl Hospital Management System v.1.0 is vulnerable to Cross Site Scripting (XSS). | |||||
| CVE-2023-34650 | 1 Small Crm Project | 1 Small Crm | 2026-06-17 | N/A | 6.1 MEDIUM |
| PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS). | |||||
| CVE-2023-34648 | 1 User Registration \& Login And User Management System With Admin Panel Project | 1 User Registration \& Login And User Management System With Admin Panel | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Cross Site Scripting vulnerability in PHPgurukl User Registration Login and User Management System with admin panel v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the signup.php. | |||||
| CVE-2023-34647 | 1 Phpgurukul | 1 Hostel Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS). | |||||
| CVE-2023-34637 | 1 Isarnet | 1 Isarflow | 2026-06-17 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in IsarNet AG IsarFlow v5.23 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the dashboard title parameter in the IsarFlow Portal. | |||||
| CVE-2023-34599 | 1 Gibbonedu | 1 Gibbon | 2026-06-17 | N/A | 6.1 MEDIUM |
| Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript code. | |||||
| CVE-2023-34565 | 1 Netbox | 1 Netbox | 2026-06-17 | N/A | 5.4 MEDIUM |
| Netbox 3.5.1 is vulnerable to Cross Site Scripting (XSS) in the "Create Wireless LAN Groups" function. | |||||
| CVE-2023-34537 | 1 Digitaldruid | 1 Hoteldruid | 2026-06-17 | N/A | 5.4 MEDIUM |
| A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data. | |||||
| CVE-2023-34486 | 1 Online Hotel Management System Project | 1 Online Hotel Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote code execution can be achieved by entering malicious code in the date selection box. | |||||
| CVE-2023-34464 | 1 Xwiki | 1 Xwiki | 2026-06-17 | N/A | 9.0 CRITICAL |
| XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.2.1 until versions 14.4.8, 14.10.5, and 15.1RC1 of org.xwiki.platform:xwiki-platform-web and any version prior to 14.4.8, 14.10.5, and 15.1.RC1 of org.xwiki.platform:xwiki-platform-web-templates, any user who can edit a document in a wiki like the user profile can create a stored cross-site scripting attack. The attack occurs by putting plain HTML code into that document and then tricking another user to visit that document with the `displaycontent` or `rendercontent` template and plain output syntax. If a user with programming rights is tricked into visiting such a URL, arbitrary actions be performed with this user's rights, impacting the confidentiality, integrity, and availability of the whole XWiki installation. This has been patched in XWiki 14.4.8, 14.10.5 and 15.1RC1 by setting the content type of the response to plain text when the output syntax is not an HTML syntax. | |||||
| CVE-2023-34461 | 1 Pybb Project | 1 Pybb | 2026-06-17 | N/A | 4.6 MEDIUM |
| PyBB is an open source bulletin board. A manual code review of the PyBB bulletin board server has revealed that a vulnerability could have been exploited in which users could submit any type of HTML tag, and have said tag run. For example, a malicious `<a>` that looks like ```<a href=javascript:alert (1)>xss</a>``` could have been used to run code through JavaScript on the client side. The problem has been patched as of commit `5defd92`, and users are advised to upgrade. Attackers do need posting privilege in order to exploit this vulnerability. This vulnerability is present within the 0.1.0 release, and users are advised to upgrade to 0.1.1. Users unable to upgrade may be able to work around the attack by either; Removing the ability to create posts, removing the `|safe` tag from the Jinja2 template titled "post.html" in templates or by adding manual validation of links in the post creation section. | |||||
| CVE-2023-34452 | 1 Getgrav | 1 Grav | 2026-06-17 | N/A | 5.4 MEDIUM |
| Grav is a flat-file content management system. In versions 1.7.42 and prior, the "/forgot_password" page has a self-reflected cross-site scripting vulnerability that can be exploited by injecting a script into the "email" parameter of the request. While this vulnerability can potentially allow an attacker to execute arbitrary code on the user's browser, the impact is limited as it requires user interaction to trigger the vulnerability. As of time of publication, a patch is not available. Server-side validation should be implemented to prevent this vulnerability. | |||||
| CVE-2023-34447 | 1 Combodo | 1 Itop | 2026-06-17 | N/A | 8.8 HIGH |
| iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0. | |||||
| CVE-2023-34446 | 1 Combodo | 1 Itop | 2026-06-17 | N/A | 8.8 HIGH |
| iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pages/preferences.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0. | |||||
| CVE-2023-34445 | 1 Combodo | 1 Itop | 2026-06-17 | N/A | 8.8 HIGH |
| Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability. | |||||
| CVE-2023-34444 | 1 Combodo | 1 Itop | 2026-06-17 | N/A | 8.8 HIGH |
| Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability. | |||||
