Total
47492 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-29508 | 1 Xwiki | 1 Xwiki | 2026-06-17 | N/A | 8.9 HIGH |
| XWiki Commons are technical libraries common to several other top level XWiki projects. A user without script rights can introduce a stored XSS by using the Live Data macro, if the last author of the content of the page has script rights. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. | |||||
| CVE-2023-29506 | 1 Xwiki | 1 Xwiki | 2026-06-17 | N/A | 5.4 MEDIUM |
| XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10. | |||||
| CVE-2023-29489 | 1 Cpanel | 1 Cpanel | 2026-06-17 | N/A | 5.3 MEDIUM |
| An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31. | |||||
| CVE-2023-29457 | 1 Zabbix | 1 Frontend | 2026-06-17 | N/A | 6.3 MEDIUM |
| Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through Action form fields, which can be sent as request to a website with a vulnerability that enables execution of malicious scripts. | |||||
| CVE-2023-29456 | 1 Zabbix | 1 Frontend | 2026-06-17 | N/A | 5.7 MEDIUM |
| URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards. | |||||
| CVE-2023-29455 | 1 Zabbix | 1 Frontend | 2026-06-17 | N/A | 5.4 MEDIUM |
| Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script is activated through a link, which sends a request to a website with a vulnerability that enables execution of malicious scripts. | |||||
| CVE-2023-29454 | 1 Zabbix | 1 Frontend | 2026-06-17 | N/A | 5.4 MEDIUM |
| Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web pages. | |||||
| CVE-2023-29452 | 1 Zabbix | 1 Zabbix | 2026-06-17 | N/A | 5.5 MEDIUM |
| Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Other” Tile provider. | |||||
| CVE-2023-29442 | 1 Zohocorp | 1 Manageengine Applications Manager | 2026-06-17 | N/A | 6.1 MEDIUM |
| Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS. | |||||
| CVE-2023-29441 | 1 Deepsoft | 1 Weblibrarian | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Robert Heller WebLibrarian plugin <= 3.5.8.1 versions. | |||||
| CVE-2023-29439 | 1 Fooplugins | 1 Foogallery | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.35 versions. | |||||
| CVE-2023-29438 | 1 Simplemodal Contact Form Project | 1 Simplemodal Contact Form | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Martin SimpleModal Contact Form (SMCF) plugin <= 1.2.9 versions. | |||||
| CVE-2023-29437 | 1 Connections-pro | 1 Connections Business Directory | 2026-06-17 | N/A | 6.5 MEDIUM |
| Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Steven A. Zahm Connections Business Directory plugin <= 10.4.36 versions. | |||||
| CVE-2023-29436 | 1 Iframe Shortcode Project | 1 Iframe Shortcode | 2026-06-17 | N/A | 6.5 MEDIUM |
| Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Flyn San IFrame Shortcode plugin <= 1.0.5 versions. | |||||
| CVE-2023-29435 | 1 Zwaply | 1 Cryptocurrency All-in-one | 2026-06-17 | N/A | 6.5 MEDIUM |
| Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Zwaply Cryptocurrency All-in-One plugin <= 3.0.19 versions. | |||||
| CVE-2023-29434 | 1 Fancythemes | 1 Optin Forms | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in FancyThemes Optin Forms – Simple List Building Plugin for WordPress plugin <= 1.3.1 versions. | |||||
| CVE-2023-29430 | 1 Cththemes | 1 Theroof | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CTHthemes TheRoof theme <= 1.0.3 versions. | |||||
| CVE-2023-29427 | 1 Tms-outsource | 1 Amelia | 2026-06-17 | N/A | 7.1 HIGH |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in TMS Booking for Appointments and Events Calendar – Amelia plugin <= 1.0.75 versions. | |||||
| CVE-2023-29424 | 1 Plainware | 1 Shiftcontroller | 2026-06-17 | N/A | 7.1 HIGH |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Plainware ShiftController Employee Shift Scheduling plugin <= 4.9.23 versions. | |||||
| CVE-2023-29423 | 1 Piwebsolution | 1 Cancel Order Request \/ Return Order \/ Repeat Order \/ Reorder For Woocommerce | 2026-06-17 | N/A | 5.9 MEDIUM |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Cancel order request / Return order / Repeat Order / Reorder for WooCommerce plugin <= 1.3.2 versions. | |||||
