Vulnerabilities (CVE)

Filtered by CWE-79
Total 47493 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-34666 1 Phpgurukul 1 Cyber Cafe Management System 2026-06-17 N/A 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Phpgurukul Cyber Cafe Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the admin username parameter.
CVE-2023-34657 1 Eyoucms 1 Eyoucms 2026-06-17 N/A 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Eyoucms v1.6.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the web_recordnum parameter.
CVE-2023-34654 1 Taogogo 1 Taocms 2026-06-17 N/A 6.1 MEDIUM
taocms <=3.0.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-34652 1 Phpgurukul 1 Hostel Management System 2026-06-17 N/A 6.1 MEDIUM
PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course.
CVE-2023-34651 1 Hospital Management System Project 1 Hospital Management System 2026-06-17 N/A 6.1 MEDIUM
PHPgurukl Hospital Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-34650 1 Small Crm Project 1 Small Crm 2026-06-17 N/A 6.1 MEDIUM
PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-34648 1 User Registration \& Login And User Management System With Admin Panel Project 1 User Registration \& Login And User Management System With Admin Panel 2026-06-17 N/A 6.1 MEDIUM
A Cross Site Scripting vulnerability in PHPgurukl User Registration Login and User Management System with admin panel v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the signup.php.
CVE-2023-34647 1 Phpgurukul 1 Hostel Management System 2026-06-17 N/A 6.1 MEDIUM
PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-34637 1 Isarnet 1 Isarflow 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in IsarNet AG IsarFlow v5.23 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the dashboard title parameter in the IsarFlow Portal.
CVE-2023-34599 1 Gibbonedu 1 Gibbon 2026-06-17 N/A 6.1 MEDIUM
Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript code.
CVE-2023-34565 1 Netbox 1 Netbox 2026-06-17 N/A 5.4 MEDIUM
Netbox 3.5.1 is vulnerable to Cross Site Scripting (XSS) in the "Create Wireless LAN Groups" function.
CVE-2023-34537 1 Digitaldruid 1 Hoteldruid 2026-06-17 N/A 5.4 MEDIUM
A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data.
CVE-2023-34486 1 Online Hotel Management System Project 1 Online Hotel Management System 2026-06-17 N/A 6.1 MEDIUM
itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote code execution can be achieved by entering malicious code in the date selection box.
CVE-2023-34464 1 Xwiki 1 Xwiki 2026-06-17 N/A 9.0 CRITICAL
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.2.1 until versions 14.4.8, 14.10.5, and 15.1RC1 of org.xwiki.platform:xwiki-platform-web and any version prior to 14.4.8, 14.10.5, and 15.1.RC1 of org.xwiki.platform:xwiki-platform-web-templates, any user who can edit a document in a wiki like the user profile can create a stored cross-site scripting attack. The attack occurs by putting plain HTML code into that document and then tricking another user to visit that document with the `displaycontent` or `rendercontent` template and plain output syntax. If a user with programming rights is tricked into visiting such a URL, arbitrary actions be performed with this user's rights, impacting the confidentiality, integrity, and availability of the whole XWiki installation. This has been patched in XWiki 14.4.8, 14.10.5 and 15.1RC1 by setting the content type of the response to plain text when the output syntax is not an HTML syntax.
CVE-2023-34461 1 Pybb Project 1 Pybb 2026-06-17 N/A 4.6 MEDIUM
PyBB is an open source bulletin board. A manual code review of the PyBB bulletin board server has revealed that a vulnerability could have been exploited in which users could submit any type of HTML tag, and have said tag run. For example, a malicious `<a>` that looks like ```<a href=javascript:alert (1)>xss</a>``` could have been used to run code through JavaScript on the client side. The problem has been patched as of commit `5defd92`, and users are advised to upgrade. Attackers do need posting privilege in order to exploit this vulnerability. This vulnerability is present within the 0.1.0 release, and users are advised to upgrade to 0.1.1. Users unable to upgrade may be able to work around the attack by either; Removing the ability to create posts, removing the `|safe` tag from the Jinja2 template titled "post.html" in templates or by adding manual validation of links in the post creation section.
CVE-2023-34452 1 Getgrav 1 Grav 2026-06-17 N/A 5.4 MEDIUM
Grav is a flat-file content management system. In versions 1.7.42 and prior, the "/forgot_password" page has a self-reflected cross-site scripting vulnerability that can be exploited by injecting a script into the "email" parameter of the request. While this vulnerability can potentially allow an attacker to execute arbitrary code on the user's browser, the impact is limited as it requires user interaction to trigger the vulnerability. As of time of publication, a patch is not available. Server-side validation should be implemented to prevent this vulnerability.
CVE-2023-34447 1 Combodo 1 Itop 2026-06-17 N/A 8.8 HIGH
iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, on `pages/UI.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.
CVE-2023-34446 1 Combodo 1 Itop 2026-06-17 N/A 8.8 HIGH
iTop is an open source, web-based IT service management platform. Prior to versions 3.0.4 and 3.1.0, when displaying `pages/preferences.php`, cross site scripting is possible. This issue is fixed in versions 3.0.4 and 3.1.0.
CVE-2023-34445 1 Combodo 1 Itop 2026-06-17 N/A 8.8 HIGH
Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2023-34444 1 Combodo 1 Itop 2026-06-17 N/A 8.8 HIGH
Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.