Vulnerabilities (CVE)

Filtered by CWE-79
Total 47493 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-30124 1 Lavalite 1 Lavalite 2026-06-17 N/A 5.4 MEDIUM
LavaLite v9.0.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-30123 1 Wuzhicms 1 Wuzhicms 2026-06-17 N/A 5.4 MEDIUM
wuzhicms v4.1.0 is vulnerable to Cross Site Scripting (XSS) in the Member Center, Account Settings.
CVE-2023-30111 1 Medicine Tracker System Project 1 Medicine Tracker System 2026-06-17 N/A 6.1 MEDIUM
Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-30106 1 Medicine Tracker System Project 1 Medicine Tracker System 2026-06-17 N/A 6.1 MEDIUM
Sourcecodester Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS) via page=about.
CVE-2023-30097 1 Totaljs 1 Messenger 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the private task field.
CVE-2023-30096 1 Totaljs 1 Messenger 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user information field.
CVE-2023-30095 1 Totaljs 1 Messenger 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in TotalJS messenger commit b6cf1c9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the channel description field.
CVE-2023-30094 1 Totaljs 1 Flow 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field in the settings module.
CVE-2023-30093 1 Onosproject 1 Onos 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter of the API documentation dashboard.
CVE-2023-2999 1 Phpmyfaq 1 Phpmyfaq 2026-06-17 N/A 6.1 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.
CVE-2023-2998 1 Phpmyfaq 1 Phpmyfaq 2026-06-17 N/A 6.1 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.
CVE-2023-2973 1 Students Online Internship Timesheet System Project 1 Students Online Internship Timesheet System 2026-06-17 3.3 LOW 2.4 LOW
A vulnerability, which was classified as problematic, has been found in SourceCodester Students Online Internship Timesheet Syste 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_company. The manipulation of the argument name with the input <script>alert(document.cookie)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230204.
CVE-2023-2960 1 Olivaekspertiz 1 Oliva Ekspertiz 2026-06-17 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliva Expertise Oliva Expertise EKS allows Cross-Site Scripting (XSS). This issue affects Oliva Expertise EKS: before 1.2.
CVE-2023-2954 1 Djangoblog Project 1 Djangoblog 2026-06-17 N/A 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master.
CVE-2023-2949 1 Open-emr 1 Openemr 2026-06-17 N/A 6.1 MEDIUM
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2948 1 Open-emr 1 Openemr 2026-06-17 N/A 6.1 MEDIUM
Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2947 1 Open-emr 1 Openemr 2026-06-17 N/A 4.8 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2925 1 Webkul 1 Krayin Crm 2026-06-17 3.3 LOW 2.4 LOW
A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part of the file /admin/contacts/organizations/edit/2 of the component Edit Person Page. The manipulation of the argument Organization leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230079. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-2922 1 Comment System Project 1 Comment System 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability classified as problematic has been found in SourceCodester Comment System 1.0. Affected is an unknown function of the file index.php of the component GET Parameter Handler. The manipulation of the argument msg leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230076.
CVE-2023-2864 1 Online Jewelry Store Project 1 Online Jewelry Store 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability was found in SourceCodester Online Jewelry Store 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file customer.php of the component POST Parameter Handler. The manipulation of the argument Custid leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-229820.