Vulnerabilities (CVE)

Filtered by CWE-79
Total 47492 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-28014 1 Hcltech 1 Bigfix Mobile 2026-06-17 N/A 6.6 MEDIUM
HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts into the application.
CVE-2023-28013 1 Hcltech 1 Verse 2026-06-17 N/A 6.5 MEDIUM
HCL Verse is susceptible to a Reflected Cross Site Scripting (XSS) vulnerability. By tricking a user into entering crafted markup a remote, unauthenticated attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information.
CVE-2023-27990 1 Zyxel 38 Atp100, Atp100 Firmware, Atp100w and 35 more 2026-06-17 N/A 4.8 MEDIUM
The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker with administrator privileges to store malicious scripts in a vulnerable device. A successful XSS attack could then result in the stored malicious scripts being executed when the user visits the Logs page of the GUI on the device.
CVE-2023-27926 1 Vektor-inc 1 Vk All In One Expansion Unit 2026-06-17 N/A 5.4 MEDIUM
Cross-site scripting vulnerability in Profile setting function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script.
CVE-2023-27925 1 Vektor-inc 1 Vk Blocks 2026-06-17 N/A 5.4 MEDIUM
Cross-site scripting vulnerability in Post function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script.
CVE-2023-27923 1 Vektor-inc 1 Vk Blocks 2026-06-17 N/A 5.4 MEDIUM
Cross-site scripting vulnerability in Tag edit function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script.
CVE-2023-27922 1 Thenewsletterplugin 1 Newsletter 2026-06-17 N/A 6.1 MEDIUM
Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.
CVE-2023-27918 1 Tms-outsource 1 Amelia 2026-06-17 N/A 6.1 MEDIUM
Cross-site scripting vulnerability in Appointment and Event Booking Calendar for WordPress - Amelia versions prior to 1.0.76 allows a remote unauthenticated attacker to inject an arbitrary script by having a user who is logging in the WordPress where the product is installed visit a malicious URL.
CVE-2023-27905 1 Jenkins 1 Update-center2 2026-06-17 N/A 9.6 CRITICAL
Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting.
CVE-2023-27898 1 Jenkins 1 Jenkins 2026-06-17 N/A 9.6 CRITICAL
Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide plugins to the configured update sites and have this message shown by Jenkins instances.
CVE-2023-27890 1 Export User Project 1 Export User 2026-06-17 N/A 5.4 MEDIUM
The Export User plugin through 2.0 for MyBB allows XSS during the process of an admin generating DSGVO data for a user, via the Custom User Title, Location, or Bio field. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2023-27888 1 Sitebridge 1 Joruri Gw 2026-06-17 N/A 5.4 MEDIUM
Cross-site scripting vulnerability in Joruri Gw Ver 3.2.5 and earlier allows a remote authenticated attacker to inject an arbitrary script via Message Memo function of the affected product.
CVE-2023-27864 1 Ibm 1 Maximo Asset Management 2026-06-17 N/A 5.4 MEDIUM
IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 249327.
CVE-2023-27777 1 Online Jewelry Shop Project 1 Online Jewelry Shop 2026-06-17 N/A 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability was discovered in Online Jewelry Shop v1.0 that allows attackers to execute arbitrary script via a crafted URL.
CVE-2023-27776 1 Online Jewelry Shop Project 1 Online Jewelry Shop 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in /index.php?page=category_list of Online Jewelry Shop v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter.
CVE-2023-27739 1 Easyxdm 1 Easyxdm 2026-06-17 N/A 6.1 MEDIUM
easyXDM 2.5 allows XSS via the xdm_e parameter.
CVE-2023-27711 1 Typecho 1 Typecho 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admin/manage-comments.php component.
CVE-2023-27641 1 Lsoft 1 Listserv 2026-06-17 N/A 6.1 MEDIUM
The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a crafted URL.
CVE-2023-27636 1 Progress 1 Sitefinity 2026-06-17 N/A 5.4 MEDIUM
Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.
CVE-2023-27631 1 Mmrs151 1 Daily Prayer Time 2026-06-17 N/A 6.5 MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in mmrs151 Daily Prayer Time plugin <= 2023.05.04 versions.