Vulnerabilities (CVE)

Filtered by CWE-79
Total 47482 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-44875 1 Kioware 1 Kioware 2026-06-17 N/A 5.4 MEDIUM
KioWare through 8.33 on Windows sets KioScriptingUrlACL.AclActions.AllowHigh for the about:blank origin, which allows attackers to obtain SYSTEM access via KioUtils.Execute in JavaScript code.
CVE-2022-44870 1 Maccms 1 Maccms 2026-06-17 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module.
CVE-2022-44787 1 Maggioli 1 Appalti \& Contratti 2026-06-17 N/A 6.1 MEDIUM
An issue was discovered in Appalti & Contratti 9.12.2. The web applications are vulnerable to a Reflected Cross-Site Scripting issue. The idPagina parameter is reflected inside the server response without any HTML encoding, resulting in XSS when the victim moves the mouse pointer inside the page. As an example, the onmouseenter attribute is not sanitized.
CVE-2022-44759 1 Hcltech 1 Hcl Leap 2026-06-17 N/A 4.6 MEDIUM
Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.
CVE-2022-44743 1 Blueglass 1 Jobs For Wordpress 2026-06-17 N/A 6.5 MEDIUM
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in BlueGlass Jobs for WordPress plugin <= 2.5.11.2 versions.
CVE-2022-44742 1 Community Events Project 1 Community Events 2026-06-17 N/A 4.8 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting vulnerability in Yannick Lefebvre Community Events plugin <= 1.4.8 versions.
CVE-2022-44741 1 Slidervilla 1 Testimonial Slider 2026-06-17 N/A 6.1 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) in David Anderson Testimonial Slider plugin <= 1.3.1 on WordPress.
CVE-2022-44736 1 Chameleon Project 1 Chameleon 2026-06-17 N/A 4.8 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Chameleon plugin <= 1.4.3 on WordPress.
CVE-2022-44735 1 Wp Clictracker Project 1 Wp Clictracker 2026-06-17 N/A 4.8 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gus Sevilla WP Clictracker plugin <= 1.0.5 versions.
CVE-2022-44734 1 Bestwebsoft 1 Car Rental 2026-06-17 N/A 4.8 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BestWebSoft Car Rental by BestWebSoft plugin <= 1.1.2 versions.
CVE-2022-44726 1 Timesheets-for-jira 1 Timesheet Tracking 2026-06-17 N/A 5.4 MEDIUM
The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view.
CVE-2022-44724 1 Stiltsoft 1 Handy Macros For Confluence 2026-06-17 N/A 8.9 HIGH
The Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability.
CVE-2022-44637 1 Redmine 1 Redmine 2026-06-17 N/A 6.1 MEDIUM
Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization in Redcloth3 Textile-formatted fields. Depending on the configuration, this may require login as a registered user.
CVE-2022-44632 1 Content-repeater Project 1 Content-repeater 2026-06-17 N/A 4.8 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Denis Buka Content Repeater – Custom Posts Simplified plugin <= 1.1.13 versions.
CVE-2022-44631 1 1app 1 1app Business Forms 2026-06-17 N/A 4.8 MEDIUM
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in 1app Technologies, Inc 1app Business Forms plugin <= 1.0.0 versions.
CVE-2022-44629 1 Catalystconnect 1 Catalyst Connect Zoho Crm Client Portal 2026-06-17 N/A 4.8 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Catalyst Connect Catalyst Connect Zoho CRM Client Portal plugin <= 2.0.0 versions.
CVE-2022-44628 1 Jumpdemand 1 4ecps Web Forms 2026-06-17 N/A 5.9 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JumpDEMAND Inc. 4ECPS Web Forms plugin <= 0.2.17 on WordPress.
CVE-2022-44625 1 Cyclodev 1 Wp Notify 2026-06-17 N/A 4.8 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting') vulnerability in Zephilou Cyklodev WP Notify plugin <= 1.2.1 versions.
CVE-2022-44594 1 Codebangers 1 All In One Time Clock Lite 2026-06-17 N/A 4.8 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Codebangers All in One Time Clock Lite plugin <= 1.3.320 versions.
CVE-2022-44591 1 Anthologize Project 1 Anthologize 2026-06-17 N/A 4.8 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anthologize plugin <= 0.8.0 on WordPress.