Vulnerabilities (CVE)

Filtered by CWE-79
Total 47482 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-45938 1 Xfinity 1 Comcast Defined Technologies Microeisbss 2026-06-17 N/A 9.0 CRITICAL
An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code Execution and privilege escalation..
CVE-2022-45916 1 Ilias 1 Ilias 2026-06-17 N/A 5.4 MEDIUM
ILIAS before 7.16 allows XSS.
CVE-2022-45913 1 Zimbra 1 Collaboration 2026-06-17 N/A 6.1 MEDIUM
An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via one of attributes in webmail URLs to execute arbitrary JavaScript code, leading to information disclosure.
CVE-2022-45911 1 Zimbra 1 Collaboration 2026-06-17 N/A 6.1 MEDIUM
An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur on the Classic UI login page by injecting arbitrary JavaScript code in the username field. This occurs before the user logs into the system, which means that even if the attacker executes arbitrary JavaScript, they will not get any sensitive information.
CVE-2022-45892 1 Planetestream 1 Planet Estream 2026-06-17 N/A 5.4 MEDIUM
In Planet eStream before 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Search Function, Comments, Batch editing tool, Content Creation, Related Media, Create new user, and Change Username.
CVE-2022-45890 1 Planetestream 1 Planet Estream 2026-06-17 N/A 6.1 MEDIUM
In Planet eStream before 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter field (e.g., search within Default.aspx with the r or fo parameter).
CVE-2022-45849 1 Colorlib 1 Activello Theme 2026-06-17 N/A 5.4 MEDIUM
Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4 versions.
CVE-2022-45848 1 Contest-gallery 1 Contest Gallery 2026-06-17 N/A 6.1 MEDIUM
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on WordPress.
CVE-2022-45843 1 Nextendweb 1 Smart Slider 3 2026-06-17 N/A 5.4 MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Nextend Smart Slider 3 plugin <= 3.5.1.9 versions.
CVE-2022-45839 1 Webhelpagency 1 Wha Puzzle 2026-06-17 N/A 5.3 MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA WHA Puzzle plugin <= 1.0.9 versions.
CVE-2022-45838 1 Reputeinfosystems 1 Arforms Form Builder 2026-06-17 N/A 6.1 MEDIUM
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARForms Form Builder plugin <= 1.5.5 versions.
CVE-2022-45837 1 Wpjam 1 Wechat Robot 2026-06-17 N/A 7.1 HIGH
Reflected Cross-Site Scripting (XSS) vulnerability in Denis 微信机器人高级版 plugin <= 6.0.1 versions.
CVE-2022-45836 1 W3eden 1 Download Manager 2026-06-17 N/A 6.3 MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.
CVE-2022-45831 1 Oxilab 1 Image Hover Effects For Elementor With Lightbox And Flipbox 2026-06-17 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in biplob018 Image Hover Effects for Elementor with Lightbox and Flipbox plugin <= 2.8 versions.
CVE-2022-45827 1 Galleryplugins 1 Video Contest 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GalleryPlugins Video Contest plugin <= 3.2 versions.
CVE-2022-45825 1 Liquidweb 1 Wpcomplete 2026-06-17 N/A 7.1 HIGH
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in iThemes WPComplete plugin <= 2.9.2 versions.
CVE-2022-45821 1 Nootheme 1 Noo Timetable 2026-06-17 N/A 6.5 MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in NooTheme Noo Timetable plugin <= 2.1.3 versions.
CVE-2022-45818 1 Essentialplugin 1 Hero Banner Ultimate 2026-06-17 N/A 6.5 MEDIUM
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Hero Banner Ultimate plugin <= 1.3.4 versions.
CVE-2022-45817 1 Gc Testimonials Project 1 Gc Testimonials 2026-06-17 N/A 5.4 MEDIUM
Cross-Site Scripting (XSS) vulnerability in Erin Garscadden GC Testimonials plugin <= 1.3.2 versions.
CVE-2022-45816 1 Dev4press 1 Gd Bbpress Attachments 2026-06-17 N/A 4.8 MEDIUM
Auth. Stored Cross-Site Scripting (XSS) vulnerability in GD bbPress Attachments plugin <= 4.3.1 on WordPress.