Vulnerabilities (CVE)

Filtered by CWE-79
Total 47492 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-28367 1 Vektor-inc 1 Vk All In One Expansion Unit 2026-06-17 N/A 5.4 MEDIUM
Cross-site scripting vulnerability in CTA post function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script.
CVE-2023-28358 1 Rocket.chat 1 Rocket.chat 2026-06-17 N/A 6.1 MEDIUM
A vulnerability has been discovered in Rocket.Chat where a markdown parsing issue in the "Search Messages" feature allows the insertion of malicious tags. This can be exploited on servers with content security policy disabled possible leading to some issues attacks like account takeover.
CVE-2023-28350 2 Faronics, Microsoft 2 Insight, Windows 2026-06-17 N/A 6.1 MEDIUM
An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized before being rendered in both the Teacher and Student Console applications, enabling an attacker to execute JavaScript in these applications. Due to the rich and highly privileged functionality offered by the Teacher Console, the ability to silently exploit Cross Site Scripting (XSS) on the Teacher Machine enables remote code execution on any connected student machine (and the teacher's machine).
CVE-2023-28347 2 Faronics, Microsoft 2 Insight, Windows 2026-06-17 N/A 9.6 CRITICAL
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that functions similarly to a Student Console, providing unauthenticated attackers with the ability to exploit XSS vulnerabilities within the Teacher Console application and achieve remote code execution as NT AUTHORITY/SYSTEM on all connected Student Consoles and the Teacher Console in a Zero Click manner.
CVE-2023-28341 1 Zohocorp 1 Manageengine Applications Manager 2026-06-17 N/A 6.1 MEDIUM
Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.
CVE-2023-28332 1 Moodle 1 Moodle 2026-06-17 N/A 6.1 MEDIUM
If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.
CVE-2023-28331 1 Moodle 1 Moodle 2026-06-17 N/A 6.1 MEDIUM
Content output by the database auto-linking filter required additional sanitizing to prevent an XSS risk.
CVE-2023-28314 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 6.1 MEDIUM
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-28313 1 Microsoft 1 Send Customer Voice Survey From Dynamics 365 2026-06-17 N/A 6.1 MEDIUM
Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability
CVE-2023-28309 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 7.6 HIGH
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-28174 1 Elightup 1 Erocket 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in eLightUp eRocket plugin <= 1.2.4 versions.
CVE-2023-28171 1 Wpchill 1 Brilliance 2026-06-17 N/A 5.4 MEDIUM
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Chill Brilliance theme <= 1.3.1 versions.
CVE-2023-28169 1 Easy Event Calendar Project 1 Easy Event Calendar 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CoreFortress Easy Event calendar plugin <= 1.0 versions.
CVE-2023-28166 1 Tags Cloud Manager Project 1 Tags Cloud Manager 2026-06-17 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Aakif Kadiwala Tags Cloud Manager plugin <= 1.0.0 versions.
CVE-2023-28158 1 Apache 1 Archiva 2026-06-17 N/A 6.5 MEDIUM
Privilege escalation via stored XSS using the file upload service to upload malicious content. The issue can be exploited only by authenticated users which can create directory name to inject some XSS content and gain some privileges such admin user.
CVE-2023-28120 2026-06-17 N/A 5.3 MEDIUM
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
CVE-2023-28106 1 Pimcore 1 Pimcore 2026-06-17 N/A 6.1 MEDIUM
Pimcore is an open source data and experience management platform. Prior to version 10.5.19, an attacker can use cross-site scripting to send a malicious script to an unsuspecting user. Users may upgrade to version 10.5.19 to receive a patch or, as a workaround, apply the patch manually.
CVE-2023-28083 2 Hp, Hpe 162 Integrated Lights-out 4, Integrated Lights-out 5, Integrated Lights-out 6 and 159 more 2026-06-17 N/A 8.3 HIGH
A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4). HPE has provided software updates to resolve this vulnerability in HPE Integrated Lights-Out.
CVE-2023-28025 1 Hcltech 1 Bigfix Modern Client Management 2026-06-17 N/A 6.6 MEDIUM
Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the server storage.
CVE-2023-28017 1 Hcltech 1 Connections 2026-06-17 N/A 5.4 MEDIUM
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise a user's account then launch other attacks.