Vulnerabilities (CVE)

Filtered by CWE-79
Total 47492 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-28499 1 Simonpedge 1 Slide Anything-responsive Content\/html Slider And Carousel 2026-06-17 N/A 5.4 MEDIUM
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML Slider and Carousel plugin <= 2.4.9 versions.
CVE-2023-28496 1 Smtp2go 1 Smtp2go 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SMTP2GO – Email Made Easy plugin <= 1.4.2 versions.
CVE-2023-28493 1 Machothemes 1 Newsmag 2026-06-17 N/A 6.5 MEDIUM
Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes NewsMag theme <= 2.4.4 versions.
CVE-2023-28490 1 Estatik 1 Estatik Mortgage Calculator 2026-06-17 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versions.
CVE-2023-28485 1 Wekan Project 1 Wekan 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (Stored XSS) vulnerability in file preview in WeKan before 6.75 allows remote authenticated users to inject arbitrary web script or HTML via names of file attachments. Any user can obtain the privilege to rename within their own board (where they have BoardAdmin access), and renameAttachment does not block XSS payloads.
CVE-2023-28477 1 Concretecms 1 Concrete Cms 2026-06-17 N/A 5.5 MEDIUM
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to stored XSS on API Integrations via the name parameter.
CVE-2023-28476 1 Concretecms 1 Concrete Cms 2026-06-17 N/A 5.4 MEDIUM
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Tags on uploaded files.
CVE-2023-28475 1 Concretecms 1 Concrete Cms 2026-06-17 N/A 6.1 MEDIUM
Concrete CMS (previously concrete5) versions 8.5.12 and below, and versions 9.0 through 9.1.3 is vulnerable to Reflected XSS on the Reply form because msgID was not sanitized.
CVE-2023-28474 1 Concretecms 1 Concrete Cms 2026-06-17 N/A 5.4 MEDIUM
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Saved Presets on search.
CVE-2023-28471 1 Concretecms 1 Concrete Cms 2026-06-17 N/A 5.4 MEDIUM
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS via a container name.
CVE-2023-28467 1 Mybb 1 Mybb 2026-06-17 N/A 6.1 MEDIUM
In MyBB before 1.8.34, there is XSS in the User CP module via the user email field.
CVE-2023-28447 2 Fedoraproject, Smarty 2 Fedora, Smarty 2026-06-17 N/A 7.1 HIGH
Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application's behavior, or unauthorized actions performed on behalf of the user. Users are advised to upgrade to either version 3.1.48 or to 4.3.1 to resolve this issue. There are no known workarounds for this vulnerability.
CVE-2023-28439 2 Ckeditor, Fedoraproject 2 Ckeditor, Fedora 2026-06-17 N/A 4.7 MEDIUM
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered affecting Iframe Dialog and Media Embed packages. The vulnerability may trigger a JavaScript code after fulfilling special conditions: using one of the affected packages on a web page with missing proper Content Security Policy configuration; initializing the editor on an element and using an element other than `<textarea>` as a base; and destroying the editor instance. This vulnerability might affect a small percentage of integrators that depend on dynamic editor initialization/destroy mechanism. A fix is available in CKEditor4 version 4.21.0. In some rare cases, a security fix may be considered a breaking change. Starting from version 4.21.0, the Iframe Dialog plugin applies the `sandbox` attribute by default, which restricts JavaScript code execution in the iframe element. To change this behavior, configure the `config.iframe_attributes` option. Also starting from version 4.21.0, the Media Embed plugin regenerates the entire content of the embed widget by default. To change this behavior, configure the `config.embed_keepOriginalContent` option. Those who choose to enable either of the more permissive options or who cannot upgrade to a patched version should properly configure Content Security Policy to avoid any potential security issues that may arise from embedding iframe elements on their web page.
CVE-2023-28435 1 Dataease 1 Dataease 2026-06-17 N/A 6.5 MEDIUM
Dataease is an open source data visualization and analysis tool. The permissions for the file upload interface is not checked so users who are not logged in can upload directly to the background. The file type also goes unchecked, users could upload any type of file. These vulnerabilities has been fixed in version 1.18.5.
CVE-2023-28429 1 Pimcore 1 Pimcore 2026-06-17 N/A 6.1 MEDIUM
Pimcore is an open source data and experience management platform. Versions prior to 10.5.19 have an unsecured tooltip field in DataObject class definition. This vulnerability has the potential to steal a user's cookie and gain unauthorized access to that user's account through the stolen cookie or redirect users to other malicious sites. Users should upgrade to version 10.5.19 or, as a workaround, apply the patch manually.
CVE-2023-28423 1 Prismtechstudios 1 Modern Footnotes 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Prism Tech Studios Modern Footnotes plugin <= 1.4.15 versions.
CVE-2023-28422 1 Mage-people 1 Event Manager And Tickets Selling For Woocommerce 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6. versions.
CVE-2023-28418 1 Mediciti Lite Project 1 Mediciti Lite 2026-06-17 N/A 5.4 MEDIUM
Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Yudlee themes Mediciti Lite theme <= 1.3.0 versions.
CVE-2023-28415 1 Xootix 1 Side Cart Woocommerce 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in XootiX Side Cart Woocommerce (Ajax) plugin <= 2.2 versions.
CVE-2023-28414 1 Apexchat 1 Apexchat 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ApexChat plugin <= 1.3.1 versions.