Vulnerabilities (CVE)

Filtered by CWE-79
Total 47486 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-25452 1 Cms Press Project 1 Cms Press 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Pretty (prettyboymp) CMS Press plugin <= 0.2.3 versions.
CVE-2023-25451 1 Wpchill 1 Cpo Content Types 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill CPO Content Types plugin <= 1.1.0 versions.
CVE-2023-25442 1 Zeno Font Resizer Project 1 Zeno Font Resizer 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in Marcel Pol Zeno Font Resizer plugin <= 1.7.9 versions.
CVE-2023-25440 1 Civicrm 1 Civicrm 2026-06-17 N/A 5.4 MEDIUM
Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/second name field.
CVE-2023-25439 1 Squarepiginteractive 1 Fusioninvoice 2026-06-17 N/A 6.1 MEDIUM
Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitrary code via the description or content fields to the expenses, tasks, and customer details.
CVE-2023-25431 1 Online Reviewer Management System Project 1 Online Reviewer Management System 2026-06-17 N/A 4.8 MEDIUM
An issue was discovered in Online Reviewer Management System v1.0. There is a XSS vulnerability via reviewer_0/admins/assessments/course/course-update.php.
CVE-2023-25365 1 Octobercms 1 October 2026-06-17 N/A 7.8 HIGH
Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3
CVE-2023-25364 2026-06-17 N/A 6.1 MEDIUM
Opswat Metadefender Core before 5.2.1 does not properly defend against potential HTML injection and XSS attacks.
CVE-2023-25347 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.
CVE-2023-25346 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter of /churchcrm/v2/family/not-found.
CVE-2023-25314 1 Wwbn 1 Avideo 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in World Wide Broadcast Network AVideo before 12.4, allows attackers to gain sensitive information via the success parameter to /user.
CVE-2023-25295 1 Gruen 1 Evewa3 2026-06-17 N/A 6.1 MEDIUM
A Cross Site Scripting (XSS) vulnerability in evewa3ajax.php in GRUEN eVEWA3 Community 31 through 53 allows attackers to obtain escalated privileges via a crafted request to the login panel.
CVE-2023-25241 1 Bgerp 1 Bgerp 2026-06-17 N/A 6.1 MEDIUM
bgERP v22.31 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.
CVE-2023-25200 2026-06-17 N/A 4.7 MEDIUM
An HTML injection vulnerability exists in the MT Safeline X-Ray X3310 webserver version NXG 19.05 that enables a remote attacker to render malicious HTML and obtain sensitive information in a victim's browser.
CVE-2023-25199 2026-06-17 N/A 5.4 MEDIUM
A reflected cross-site scripting (XSS) vulnerability exists in the MT Safeline X-Ray X3310 webserver version NXG 19.05 that enables a remote attacker to execute JavaScript code and obtain sensitive information in a victim's browser.
CVE-2023-25172 1 Discourse 1 Discourse 2026-06-17 N/A 4.4 MEDIUM
Discourse is an open-source discussion platform. Prior to version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches, a maliciously crafted URL can be included in a user's full name field to to carry out cross-site scripting attacks on sites with a disabled or overly permissive CSP (Content Security Policy). Discourse's default CSP prevents this vulnerability. The vulnerability is patched in version 3.0.1 of the `stable` branch and version 3.1.0.beta2 of the `beta` and `tests-passed` branches. As a workaround, enable and/or restore your site's CSP to the default one provided with Discourse.
CVE-2023-25154 1 Misskey 1 Misskey 2026-06-17 N/A 7.1 HIGH
Misskey is an open source, decentralized social media platform. In versions prior to 13.5.0 the link to the instance to the sender that appears when viewing a user or note received through ActivityPub is not properly validated, so by inserting a URL with a javascript scheme an attacker may execute JavaScript code in the context of the recipient. This issue has been fixed in version 13.5.0. Users are advised to upgrade. Users unable to upgrade should not "view on remote" for untrusted instances.
CVE-2023-25077 1 Ec-cube 1 Ec-cube 2026-06-17 N/A 5.4 MEDIUM
Cross-site scripting vulnerability in Authentication Key Settings of EC-CUBE 4.0.0 to 4.0.6-p2, EC-CUBE 4.1.0 to 4.1.2-p1, and EC-CUBE 4.2.0 allows a remote authenticated attacker to inject an arbitrary script.
CVE-2023-25064 1 Wp Htpasswd Project 1 Wp Htpasswd 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Matteo Candura WP htpasswd plugin <= 1.7 versions.
CVE-2023-25063 1 Anadnet 1 Quick Page\/post Redirect Plugin 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anadnet Quick Page/Post Redirect Plugin plugin <= 5.2.3 versions.