Vulnerabilities (CVE)

Filtered by CWE-79
Total 47493 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-33725 1 Broadleafcommerce 1 Broadleaf Commerce 2026-06-17 N/A 6.1 MEDIUM
Broadleaf 5.x and 6.x (including 5.2.25-GA and 6.2.6-GA) was discovered to contain a cross-site scripting (XSS) vulnerability via a customer signup with a crafted email address. This is fixed in 6.2.6.1-GA.
CVE-2023-33661 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities were discovered in Church CRM v4.5.3 in GroupReports.php via GroupRole, ReportModel, and OnlyCart parameters.
CVE-2023-33599 1 Easyimages2.0 Project 1 Easyimages2.0 2026-06-17 N/A 6.1 MEDIUM
EasyImages2.0 ≤ 2.8.1 is vulnerable to Cross Site Scripting (XSS) via viewlog.php.
CVE-2023-33591 1 User Registration \& Login And User Management System Project 1 User Registration \& Login And User Management System 2026-06-17 N/A 6.1 MEDIUM
User Registration & Login and User Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-result.php.
CVE-2023-33580 1 Phpgurukul 1 Student Study Center Management System 2026-06-17 N/A 4.8 MEDIUM
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" field on Admin Profile page.
CVE-2023-33564 1 Phpjabbers 1 Time Slots Booking Calendar 2026-06-17 N/A 6.1 MEDIUM
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.
CVE-2023-33560 1 Phpjabbers 1 Time Slots Booking Calendar 2026-06-17 N/A 6.1 MEDIUM
There is a Cross Site Scripting (XSS) vulnerability in "cid" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.
CVE-2023-33548 2026-06-17 N/A 6.8 MEDIUM
Cross Site Scripting (XSS) vulnerability in ASUS RT-AC51U with firmware versions up to and including 3.0.0.4.380.8591 allows attackers to run arbitrary code via the WPA Pre-Shared Key field.
CVE-2023-33528 1 Halo 1 Halo 2026-06-17 N/A 6.1 MEDIUM
halo v1.6.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-33515 1 Softexpert 1 Excellence Suite 2026-06-17 N/A 5.4 MEDIUM
SoftExpert Excellence Suite 2.1.9 is vulnerable to Cross Site Scripting (XSS) via query screens.
CVE-2023-33495 1 Craftcms 1 Craft Cms 2026-06-17 N/A 6.1 MEDIUM
Craft CMS through 4.4.9 is vulnerable to HTML Injection.
CVE-2023-33492 1 Eyoucms 1 Eyoucms 2026-06-17 N/A 5.4 MEDIUM
EyouCMS 1.6.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-33408 1 Minical 1 Minical 2026-06-17 N/A 5.4 MEDIUM
Minical 1.0.0 is vulnerable to Cross Site Scripting (XSS). The vulnerability exists due to insufficient input validation in the application's user input handling in the security_helper.php file.
CVE-2023-33394 1 Skycaiji 1 Skycaiji 2026-06-17 N/A 5.4 MEDIUM
skycaiji v2.5.4 is vulnerable to Cross Site Scripting (XSS). Attackers can achieve backend XSS by deploying malicious JSON data.
CVE-2023-33387 1 Datev 1 Eg Personal-management System Comfort\/comfort Plus 2026-06-17 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0 to v16.1.1 P4 allows attackers to steal targeted users' login data by sending a crafted link.
CVE-2023-33356 1 Thecosy 1 Icecms 2026-06-17 N/A 5.4 MEDIUM
IceCMS v1.0.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-33336 1 Sophos 1 Web Appliance 2026-06-17 N/A 4.8 MEDIUM
Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes.
CVE-2023-33335 1 Sophos 1 Iview 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed.
CVE-2023-33332 1 Woocommerce Product Vendors Project 1 Woocommerce Product Vendors 2026-06-17 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Product Vendors plugin <= 2.1.76 versions.
CVE-2023-33329 1 Custom Post Type Generator Project 1 Custom Post Type Generator 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Hijiri Custom Post Type Generator plugin <= 2.4.2 versions.