Vulnerabilities (CVE)

Filtered by CWE-79
Total 47486 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-24230 1 Formwork Project 1 Formwork 2026-06-17 N/A 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component /formwork/panel/dashboard of Formwork v1.12.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page title parameter.
CVE-2023-24203 1 Oretnom23 1 Simple Customer Relationship Management System 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).
CVE-2023-24197 1 Oretnom23 1 Online Food Ordering System 2026-06-17 N/A 6.1 MEDIUM
Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php.
CVE-2023-24195 1 Oretnom23 1 Online Food Ordering System 2026-06-17 N/A 6.1 MEDIUM
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php.
CVE-2023-24194 1 Oretnom23 1 Online Food Ordering System 2026-06-17 N/A 6.1 MEDIUM
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in navbar.php.
CVE-2023-24192 1 Oretnom23 1 Online Food Ordering System 2026-06-17 N/A 6.1 MEDIUM
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php.
CVE-2023-24191 1 Oretnom23 1 Online Food Ordering System 2026-06-17 N/A 6.1 MEDIUM
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php.
CVE-2023-24182 1 Openwrt 1 Openwrt 2026-06-17 N/A 5.4 MEDIUM
LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /system/sshkeys.js.
CVE-2023-24181 1 Openwrt 1 Luci 2026-06-17 N/A 5.4 MEDIUM
LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openvpn/pageswitch.htm.
CVE-2023-24086 1 Slims Project 1 Slims 2026-06-17 N/A 6.1 MEDIUM
SLIMS v9.5.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /customs/loan_by_class.php?reportView.
CVE-2023-24081 1 Go-redrock 1 Tutortrac 2026-06-17 N/A 5.4 MEDIUM
Multiple stored cross-site scripting (XSS) vulnerabilities in Redrock Software TutorTrac before v4.2.170210 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the reason and location fields of the visits listing page.
CVE-2023-24065 1 Nosh Chartingsystem Project 1 Nosh Chartingsystem 2026-06-17 N/A 5.4 MEDIUM
NOSH 4a5cfdb allows stored XSS via the create user page. For example, a first name (of a physician, assistant, or billing user) can have a JavaScript payload that is executed upon visiting the /users/2/1 page. This may allow attackers to steal Protected Health Information because the product is for health charting.
CVE-2023-24050 1 Connectize 2 Ac21000 G6, Ac21000 G6 Firmware 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary code via crafted string when setting the Wi-Fi password in the admin panel.
CVE-2023-24031 1 Zimbra 1 Collaboration 2026-06-17 N/A 6.1 MEDIUM
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 8.8.15. XSS can occur, via one of attributes of the webmail /h/ endpoint, to execute arbitrary JavaScript code, leading to information disclosure.
CVE-2023-24026 1 Misp-project 1 Misp 2026-06-17 N/A 6.1 MEDIUM
In MISP 2.4.167, app/webroot/js/event-graph.js has an XSS vulnerability via an event-graph preview payload.
CVE-2023-24009 1 Wpazure 1 Upfrontwp 2026-06-17 N/A 5.4 MEDIUM
Auth. (subscriber+) Reflected Cross-site Scripting (XSS) vulnerability in Wpazure Themes Upfrontwp theme <= 1.1 versions.
CVE-2023-24006 1 Linksoftwarellc 1 Wp Terms Popup 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Link Software LLC WP Terms Popup plugin <= 2.6.0 versions.
CVE-2023-24005 1 Winwar 1 Inline Tweet Sharer 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media Inline Tweet Sharer – Twitter Sharing Plugin plugin <= 2.5.3 versions.
CVE-2023-24004 1 Wpdevart 1 Download Image And Video Lightbox\, Image Popup 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPdevart Image and Video Lightbox, Image PopUp plugin <= 2.1.5 versions.
CVE-2023-24003 1 Timersys 1 Wp Popups 2026-06-17 N/A 6.5 MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Timersys WP Popups – WordPress Popup plugin <= 2.1.4.8 versions.