Vulnerabilities (CVE)

Filtered by CWE-79
Total 47493 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-31934 1 Phpgurukul 1 Rail Pass Management System 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the adminname parameter of admin-profile.php.
CVE-2023-31928 1 Broadcom 1 Brocade Fabric Operating System 2026-06-17 N/A 6.3 MEDIUM
A reflected cross-site scripting (XSS) vulnerability exists in Brocade Webtools PortSetting.html of Brocade Fabric OS version before Brocade Fabric OS v9.2.0 that could allow a remote unauthenticated attacker to execute arbitrary JavaScript code in a target user’s session with the Brocade Webtools application.
CVE-2023-31862 1 Jizhicms 1 Jizhicms 2026-06-17 N/A 5.4 MEDIUM
jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is only filtered in the front end, without being filtered in the background, which allows attackers to publish an article containing malicious JavaScript scripts by modifying the request package.
CVE-2023-31860 1 Wuzhicms 1 Wuzhicms 2026-06-17 N/A 5.4 MEDIUM
Wuzhi CMS v3.1.2 has a storage type XSS vulnerability in the backend of the Five Finger CMS b2b system.
CVE-2023-31853 1 Cudy 2 Lt400, Lt400 Firmware 2026-06-17 N/A 6.1 MEDIUM
Cudy LT400 1.13.4 is vulnerable Cross Site Scripting (XSS) in /cgi-bin/luci/admin/network/bandwidth via the icon parameter.
CVE-2023-31852 1 Cudy 2 Lt400, Lt400 Firmware 2026-06-17 N/A 6.1 MEDIUM
Cudy LT400 1.13.4 is vulnerable to Cross Site Scripting (XSS) in cgi-bin/luci/admin/network/wireless/config via the iface parameter.
CVE-2023-31851 1 Cudy 2 Lt400, Lt400 Firmware 2026-06-17 N/A 6.1 MEDIUM
Cudy LT400 1.13.4 is has a cross-site scripting (XSS) vulnerability in /cgi-bin/luci/admin/network/wireless/status via the iface parameter.
CVE-2023-31816 1 Content Management System Project 1 Content Management System 2026-06-17 N/A 6.1 MEDIUM
IT Sourcecode Content Management System Project In PHP and MySQL With Source Code 1.0.0 is vulnerable to Cross Site Scripting (XSS) via /ecodesource/search_list.php.
CVE-2023-31779 1 Wekan Project 1 Wekan 2026-06-17 N/A 5.4 MEDIUM
Wekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript code in in "Reaction to comment" feature.
CVE-2023-31757 1 Dedecms 1 Dedecms 2026-06-17 N/A 5.4 MEDIUM
DedeCMS up to v5.7.108 is vulnerable to XSS in sys_info.php via parameters 'edit___cfg_powerby' and 'edit___cfg_beian'
CVE-2023-31754 1 Optimizely 1 Optimizely Cms 2026-06-17 N/A 4.8 MEDIUM
Optimizely CMS UI before v12.16.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Admin panel.
CVE-2023-31705 1 Task Reminder System Project 1 Task Reminder System 2026-06-17 N/A 5.4 MEDIUM
A Reflected Cross-site scripting (XSS) vulnerability in Sourcecodester Task Reminder System 1.0 allows an authenticated user to inject malicious javascript into the page parameter.
CVE-2023-31703 1 Escanav 1 Escan Management Console 2026-06-17 N/A 9.0 CRITICAL
Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter.
CVE-2023-31699 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 4.8 MEDIUM
ChurchCRM v4.5.4 is vulnerable to Reflected Cross-Site Scripting (XSS) via image file.
CVE-2023-31698 1 Bludit 1 Bludit 2026-06-17 N/A 5.4 MEDIUM
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).
CVE-2023-31664 1 Wso2 1 Api Manager 2026-06-17 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in /authenticationendpoint/login.do of WSO2 API Manager before 4.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tenantDomain parameter.
CVE-2023-31584 1 Silicon Project 1 Silicon 2026-06-17 N/A 6.1 MEDIUM
GitHub repository cu/silicon commit a9ef36 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the User Input field.
CVE-2023-31548 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 5.4 MEDIUM
A stored Cross-site scripting (XSS) vulnerability in the FundRaiserEditor.php component of ChurchCRM v4.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2023-31546 1 Dedebiz 1 Dedebiz 2026-06-17 N/A 9.6 CRITICAL
Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.
CVE-2023-31544 1 Alkacon 1 Opencms 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in alkacon-OpenCMS v11.0.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field under the Upload Image module.