Vulnerabilities (CVE)

Filtered by CWE-79
Total 47482 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-46332 1 Proofpoint 1 Enterprise Protection 2026-06-17 N/A 9.6 CRITICAL
The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin privileges within the user interface. This affects all versions 8.19.0 and below.
CVE-2022-46287 1 Jacic 1 Electronic Bidding Core System 2026-06-17 N/A 6.1 MEDIUM
Cross-site scripting vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.
CVE-2022-46181 1 Gotify 1 Server 2026-06-17 N/A 6.1 MEDIUM
Gotify server is a simple server for sending and receiving messages in real-time per WebSocket. Versions prior to 2.2.2 contain an XSS vulnerability that allows authenticated users to upload .html files. An attacker could execute client side scripts **if** another user opened a link. The attacker could potentially take over the account of the user that clicked the link. The Gotify UI won't natively expose such a malicious link, so an attacker has to get the user to open the malicious link in a context outside of Gotify. The vulnerability has been fixed in version 2.2.2. As a workaround, you can block access to non image files via a reverse proxy in the `./image` directory.
CVE-2022-46180 1 Discourse 1 Mermaid 2026-06-17 N/A 5.0 MEDIUM
Discourse Mermaid (discourse-mermaid-theme-component) allows users of Discourse, open-source forum software, to create graphs using the Mermaid syntax. Users of discourse-mermaid-theme-component version 1.0.0 who can create posts are able to inject arbitrary HTML on that post. The issue has been fixed on the `main` branch of the GitHub repository, with 1.1.0 named as a patched version. Admins can update the theme component through the admin UI. As a workaround, admins can temporarily disable discourse-mermaid-theme-component.
CVE-2022-46165 1 Syncthing 1 Syncthing 2026-06-17 N/A 4.6 MEDIUM
Syncthing is an open source, continuous file synchronization program. In versions prior to 1.23.5 a compromised instance with shared folders could sync malicious files which contain arbitrary HTML and JavaScript in the name. If the owner of another device looks over the shared folder settings and moves the mouse over the latest sync, a script could be executed to change settings for shared folders or add devices automatically. Additionally adding a new device with a malicious name could embed HTML or JavaScript inside parts of the page. As a result the webUI may be subject to a stored cross site scripting attack. This issue has been addressed in version 1.23.5. Users are advised to upgrade. Users unable to upgrade should avoid sharing folders with untrusted users.
CVE-2022-46162 1 Discourse 1 Discourse Bbcode 2026-06-17 N/A 8.8 HIGH
discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rendering content generated with the discourse-bccode plugin. This vulnerability only affects sites which have the discourse-bbcode plugin installed and enabled. This issue is patched in commit 91478f5. As a workaround, ensure that the Content Security Policy is enabled and monitor any posts that contain bbcode.
CVE-2022-46151 1 Pinterest 1 Querybook 2026-06-17 N/A 6.3 MEDIUM
Querybook is an open source data querying UI. In affected versions user provided data is not escaped in the error field of the auth callback url in `querybook/server/app/auth/oauth_auth.py` and `querybook/server/app/auth/okta_auth.py`. This may allow attackers to perform reflected cross site scripting (XSS) if Content Security Policy (CSP) is not enabled or `unsafe-inline` is allowed. Users are advised to upgrade to the latest, patched version of querybook (version 3.14.2 or greater). Users unable to upgrade may enable CSP and not allow unsafe-inline or manually escape query parameters in a reverse proxy.
CVE-2022-46148 1 Discourse 1 Discourse 2026-06-17 N/A 7.1 HIGH
Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.beta11 and prior on the `beta` and `tests-passed` branches, users composing malicious messages and navigating to drafts page could self-XSS. This vulnerability can lead to a full XSS on sites which have modified or disabled Discourse’s default Content Security Policy. This issue is patched in the latest stable, beta and tests-passed versions of Discourse.
CVE-2022-46147 1 Openedx 1 Xblock-drag-and-drop-v2 2026-06-17 N/A 8.4 HIGH
Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0.0 are vulnerable to cross-site scripting in multiple XBlock Fields. Any platform that has deployed the XBlock may be impacted. Version 3.0.0 contains a patch for this issue. There are no known workarounds.
CVE-2022-46128 1 Phpgurukul 1 Doctor Appointment Management System 2026-06-17 N/A 6.1 MEDIUM
phpgurukul Doctor Appointment Management System V 1.0.0 is vulnerable to Cross Site Scripting (XSS) via searchdata=.
CVE-2022-46096 1 Covid-19 Directory On Vaccination System Project 1 Covid-19 Directory On Vaccination System 2026-06-17 N/A 6.1 MEDIUM
A Cross site scripting (XSS) vulnerability in Sourcecodester Online Covid-19 Directory on Vaccination System v1.0 allows attackers to execute arbitrary code via the txtfullname parameter or txtphone parameter to register.php without logging in.
CVE-2022-46095 1 Covid-19 Directory On Vaccination System Project 1 Covid-19 Directory On Vaccination System 2026-06-17 N/A 6.1 MEDIUM
Sourcecodester Covid-19 Directory on Vaccination System 1.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via verification.php because the program does not verify the txtvaccinationID parameter.
CVE-2022-46091 1 Oretnom23 1 Online Flight Booking Management System 2026-06-17 N/A 4.7 MEDIUM
Cross Site Scripting (XSS) vulnerability in the feedback form of Online Flight Booking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the airline parameter.
CVE-2022-46089 1 Oretnom23 1 Online Flight Booking Management System 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in the add-airline form of Online Flight Booking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the airline parameter.
CVE-2022-46088 1 Oretnom23 1 Online Flight Booking Management System 2026-06-17 N/A 6.1 MEDIUM
Online Flight Booking Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the feedback form.
CVE-2022-46087 1 Cloudschool Project 1 Cloudschool 2026-06-17 N/A 5.4 MEDIUM
CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification received by the admin user.
CVE-2022-46073 1 Helmet Store Showroom Project 1 Helmet Store Showroom 2026-06-17 N/A 6.1 MEDIUM
Helmet Store Showroom 1.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-46058 1 Aerocms Project 1 Aerocms 2026-06-17 N/A 4.8 MEDIUM
AeroCMS v0.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.
CVE-2022-45990 1 Ecommerce-website Project 1 Ecommerce-website 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail parameter.
CVE-2022-45970 1 Alistgo 1 Alist 2026-06-17 N/A 5.4 MEDIUM
Alist v3.5.1 is vulnerable to Cross Site Scripting (XSS) via the bulletin board.