Total
47493 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-32116 | 1 Totalpress | 1 Custom Post Types | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in TotalPress.Org Custom post types, Custom Fields & more plugin <= 4.0.12 versions. | |||||
| CVE-2023-32109 | 1 Eduva | 1 Albo Pretorio Online | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ignazio Scimone Albo Pretorio On line plugin <= 4.6.3 versions. | |||||
| CVE-2023-32108 | 1 Eduva | 1 Albo Pretorio Online | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ignazio Scimone Albo Pretorio On line plugin <= 4.6.3 versions. | |||||
| CVE-2023-32107 | 1 Ays-pro | 1 Photo Gallery | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.1.3 versions. | |||||
| CVE-2023-32106 | 1 Fahad Mahmood | 1 Wp Docs | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Fahad Mahmood WP Docs plugin <= 1.9.9 versions. | |||||
| CVE-2023-32105 | 1 Wp-pizza | 1 Wppizza | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ollybach WPPizza – A Restaurant Plugin plugin <= 3.17.1 versions. | |||||
| CVE-2023-32103 | 1 Themepalace | 1 Tp Education | 2026-06-17 | N/A | 6.5 MEDIUM |
| Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Theme Palace TP Education plugin <= 4.4 versions. | |||||
| CVE-2023-32102 | 1 Pexlechris | 1 Library Viewer | 2026-06-17 | N/A | 6.5 MEDIUM |
| Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Pexle Chris Library Viewer plugin <= 2.0.6 versions. | |||||
| CVE-2023-32089 | 1 Pega | 1 Platform | 2026-06-17 | N/A | 4.6 MEDIUM |
| Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description | |||||
| CVE-2023-32088 | 1 Pega | 1 Platform | 2026-06-17 | N/A | 4.6 MEDIUM |
| Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation | |||||
| CVE-2023-32087 | 1 Pega | 1 Platform | 2026-06-17 | N/A | 4.6 MEDIUM |
| Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation | |||||
| CVE-2023-32072 | 1 Enalean | 1 Tuleap | 2026-06-17 | N/A | 4.8 MEDIUM |
| Tuleap is an open source tool for end to end traceability of application and system developments. Tuleap Community Edition prior to version 14.8.99.60 and Tuleap Enterprise edition prior to 14.8-3 and 14.7-7, the logs of the triggered Jenkins job URLs are not properly escaped. A malicious Git administrator can setup a malicious Jenkins hook to make a victim, also a Git administrator, execute uncontrolled code. Tuleap Community Edition 14.8.99.60, Tuleap Enterprise Edition 14.8-3, and Tuleap Enterprise Edition 14.7-7 contain a patch for this issue. | |||||
| CVE-2023-32071 | 1 Xwiki | 1 Xwiki | 2026-06-17 | N/A | 9.0 CRITICAL |
| XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to execute javascript with the right of any user by leading him to a special URL on the wiki targeting a page which contains an attachment. This has been patched in XWiki 15.0-rc-1, 14.10.4, and 14.4.8. The easiest possible workaround is to edit file `<xwiki app>/templates/importinline.vm` and apply the modification described in commit 28905f7f518cc6f21ea61fe37e9e1ed97ef36f01. | |||||
| CVE-2023-32070 | 1 Xwiki | 2 Rendering, Xwiki | 2026-06-17 | N/A | 9.0 CRITICAL |
| XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax. This has been patched in XWiki 14.6-rc-1. There are no known workarounds apart from upgrading to a fixed version. | |||||
| CVE-2023-32066 | 1 Anuko | 1 Time Tracker | 2026-06-17 | N/A | 5.4 MEDIUM |
| Time Tracker is an open source time tracking system. The week view plugin in Time Tracker versions 1.22.11.5782 and prior was not escaping titles for notes in week view table. Because of that, it was possible for a logged in user to enter notes with elements of JavaScript. Such script could then be executed in user browser on subsequent requests to week view. This issue is fixed in version 1.22.12.5783. As a workaround, use `htmlspecialchars` when calling `$field->setTitle` on line #245 in the `week.php` file, as happens in version 1.22.12.5783. | |||||
| CVE-2023-32024 | 1 Microsoft | 1 Power Apps | 2026-06-17 | N/A | 3.0 LOW |
| Microsoft Power Apps Spoofing Vulnerability | |||||
| CVE-2023-32000 | 1 Ui | 1 Unifi Network Application | 2026-06-17 | N/A | 4.8 MEDIUM |
| A Cross-Site Scripting (XSS) vulnerability found in UniFi Network (Version 7.3.83 and earlier) allows a malicious actor with Site Administrator credentials to escalate privileges by persuading an Administrator to visit a malicious web page. | |||||
| CVE-2023-31995 | 1 Hanwhavision | 236 Ane-l6012r, Ane-l6012r Firmware, Ane-l7012r and 233 more | 2026-06-17 | N/A | 5.4 MEDIUM |
| Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Cross Site Scripting (XSS). | |||||
| CVE-2023-31942 | 1 Online Travel Agency System Project | 1 Online Travel Agency System | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the description parameter in insert.php. | |||||
| CVE-2023-31935 | 1 Phpgurukul | 1 Rail Pass Management System | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the emial parameter of admin-profile.php. | |||||
