Vulnerabilities (CVE)

Filtered by CWE-79
Total 47482 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-42225 1 Fit2cloud 1 Lina 2026-06-17 N/A 5.4 MEDIUM
Jumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of user input, which can execute any javascript under admin's permission.
CVE-2022-42206 1 Phpgurukul 1 Hospital Management System 2026-06-17 N/A 5.4 MEDIUM
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via doctor/view-patient.php, admin/view-patient.php, and view-medhistory.php.
CVE-2022-42205 1 Phpgurukul 1 Hospital Management System 2026-06-17 N/A 5.4 MEDIUM
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via add-patient.php.
CVE-2022-42202 1 Tp-link 2 Tl-wr841n, Tl-wr841n Firmware 2026-06-17 N/A 6.1 MEDIUM
TP-Link TL-WR841N 8.0 4.17.16 Build 120201 Rel.54750n is vulnerable to Cross Site Scripting (XSS).
CVE-2022-42200 1 Simple Exam Reviewer Management System Project 1 Simple Exam Reviewer Management System 2026-06-17 N/A 5.4 MEDIUM
Simple Exam Reviewer Management System v1.0 is vulnerable to Stored Cross Site Scripting (XSS) via the Exam List.
CVE-2022-42187 1 Hustoj 1 Hustoj 2026-06-17 N/A 6.1 MEDIUM
Hustoj 22.09.22 has a XSS Vulnerability in /admin/problem_judge.php.
CVE-2022-42147 1 Keking 1 Kkfileview 2026-06-17 N/A 6.1 MEDIUM
kkFileView 4.0 is vulnerable to Cross Site Scripting (XSS) via controller\ Filecontroller.java.
CVE-2022-42141 1 Deltaww 2 Dx-2100-l1-cn, Dx-2100-l1-cn Firmware 2026-06-17 N/A 5.4 MEDIUM
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter.
CVE-2022-42111 1 Liferay 3 Digital Experience Platform, Dxp, Liferay Portal 2026-06-17 N/A 5.4 MEDIUM
A Cross-site scripting (XSS) vulnerability in the Sharing module's user notification in Liferay Portal 7.2.1 through 7.4.2, and Liferay DXP 7.2 before fix pack 19, and 7.3 before update 4 allows remote attackers to inject arbitrary web script or HTML by sharing an asset with a crafted payload.
CVE-2022-42110 1 Liferay 3 Digital Experience Platform, Dxp, Liferay Portal 2026-06-17 N/A 6.1 MEDIUM
A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML.
CVE-2022-42100 1 Klik Project 1 Klik 2026-06-17 N/A 5.4 MEDIUM
KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location input reply-form.
CVE-2022-42099 1 Klik Project 1 Klik 2026-06-17 N/A 5.4 MEDIUM
KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location Forum Subject input.
CVE-2022-42097 1 Backdropcms 1 Backdrop 2026-06-17 N/A 4.8 MEDIUM
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .
CVE-2022-42096 1 Backdropcms 1 Backdrop Cms 2026-06-17 N/A 4.8 MEDIUM
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.
CVE-2022-42095 1 Backdropcms 1 Backdrop Cms 2026-06-17 N/A 4.8 MEDIUM
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.
CVE-2022-42094 1 Backdropcms 1 Backdrop 2026-06-17 N/A 4.8 MEDIUM
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.
CVE-2022-42071 1 Oretnom23 1 Online Birth Certificate Management System 2026-06-17 N/A 6.1 MEDIUM
Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.
CVE-2022-42069 1 Oretnom23 1 Online Birth Certificate Management System 2026-06-17 N/A 5.4 MEDIUM
Online Birth Certificate Management System version 1.0 suffers from a persistent Cross Site Scripting (XSS) vulnerability.
CVE-2022-42066 1 Projectworlds 1 Online Examination System 2026-06-17 N/A 6.1 MEDIUM
Online Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php.
CVE-2022-42054 1 Gl-inet 1 Goodcloud 2026-06-17 N/A 5.4 MEDIUM
Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Company Name and Description text fields.