Vulnerabilities (CVE)

Filtered by CWE-79
Total 47493 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-33208 1 Cookie Monster Project 1 Cookie Monster 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gsmith Cookie Monster plugin <= 1.51 versions.
CVE-2023-33197 1 Craftcms 1 Craft Cms 2026-06-17 N/A 5.5 MEDIUM
Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.
CVE-2023-33196 1 Craftcms 1 Craft Cms 2026-06-17 N/A 5.5 MEDIUM
Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.
CVE-2023-33195 1 Craftcms 1 Craft Cms 2026-06-17 N/A 5.0 MEDIUM
Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This issue was patched in version 4.4.6.
CVE-2023-33194 2 Craftcms, Craftercms 2 Craft Cms, Craftercms 2026-06-17 N/A 3.7 LOW
Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was patched in version 4.4.6.
CVE-2023-33186 1 Zulip 1 Zulip Server 2026-06-17 N/A 8.2 HIGH
Zulip is an open-source team collaboration tool with unique topic-based threading that combines the best of email and chat to make remote work productive and delightful. The main development branch of Zulip Server from May 2, 2023 and later, including beta versions 7.0-beta1 and 7.0-beta2, is vulnerable to a cross-site scripting vulnerability in tooltips on the message feed. An attacker who can send messages could maliciously craft a topic for the message, such that a victim who hovers the tooltip for that topic in their message feed triggers execution of JavaScript code controlled by the attacker.
CVE-2023-33171 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 8.2 HIGH
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-33159 1 Microsoft 1 Sharepoint Server 2026-06-17 N/A 8.8 HIGH
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2023-33132 1 Microsoft 1 Sharepoint Server 2026-06-17 N/A 6.3 MEDIUM
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2023-33130 1 Microsoft 1 Sharepoint Server 2026-06-17 N/A 7.3 HIGH
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2023-33007 1 Jenkins 1 Loadcomplete Support 2026-06-17 N/A 5.4 MEDIUM
Jenkins LoadComplete support Plugin 1.0 and earlier does not escape the LoadComplete test name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVE-2023-33002 1 Jenkins 1 Testcomplete Support 2026-06-17 N/A 5.4 MEDIUM
Jenkins TestComplete support Plugin 2.8.1 and earlier does not escape the TestComplete project name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVE-2023-32984 1 Jenkins 1 Testng Results 2026-06-17 N/A 5.4 MEDIUM
Jenkins TestNG Results Plugin 730.v4c5283037693 and earlier does not escape several values that are parsed from TestNG report files and displayed on the plugin's test information pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a crafted TestNG report file.
CVE-2023-32977 1 Jenkins 1 Pipeline\ 2026-06-17 N/A 5.4 MEDIUM
Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set build display names immediately.
CVE-2023-32969 1 Qnap 3 Qts, Quts Hero, Qutscloud 2026-06-17 N/A 4.9 MEDIUM
A cross-site scripting (XSS) vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QuTScloud c5.1.5.2651 and later QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later
CVE-2023-32965 1 Crudlab 1 Jazz Popups 2026-06-17 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CRUDLab Jazz Popups plugin <= 1.8.7 versions.
CVE-2023-32962 1 Hasthemes 1 Wishsuite 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in HasTheme WishSuite – Wishlist for WooCommerce plugin <= 1.3.4 versions.
CVE-2023-32961 1 Zotpress Project 1 Zotpress 2026-06-17 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <= 7.3.3 versions.
CVE-2023-32958 1 Nosegraze 1 Novelist 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nose Graze Novelist plugin <= 1.2.0 versions.
CVE-2023-32957 1 Dazzlersoft 1 Team Members Showcase 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dazzlersoft Team Members Showcase plugin <= 1.3.4 versions.