Vulnerabilities (CVE)

Filtered by CWE-79
Total 47482 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-40348 1 Intern Record System Project 1 Intern Record System 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'name' and 'email' parameters, allows attackers to execute arbitrary code.
CVE-2022-40325 1 Sysaid 1 Help Desk 2026-06-17 N/A 6.1 MEDIUM
SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262.
CVE-2022-40324 1 Sysaid 1 Help Desk 2026-06-17 N/A 6.1 MEDIUM
SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258.
CVE-2022-40323 1 Sysaid 1 Help Desk 2026-06-17 N/A 6.1 MEDIUM
SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241.
CVE-2022-40322 1 Sysaid 1 Help Desk 2026-06-17 N/A 6.1 MEDIUM
SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579.
CVE-2022-40317 1 Openkm 1 Openkm 2026-06-17 N/A 5.4 MEDIUM
OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.
CVE-2022-40313 2 Fedoraproject, Moodle 3 Extra Packages For Enterprise Linux, Fedora, Moodle 2026-06-17 N/A 7.1 HIGH
Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.
CVE-2022-40311 1 Fatcatapps 1 Analytics Cat 2026-06-17 N/A 4.8 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) in Fatcat Apps Analytics Cat plugin <= 1.0.9 on WordPress.
CVE-2022-40290 1 Phppointofsale 1 Php Point Of Sale 2026-06-17 N/A 6.1 MEDIUM
The application was vulnerable to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the barcode generation functionality, allowing attackers to generate an unsafe link that could compromise users.
CVE-2022-40289 1 Phppointofsale 1 Php Point Of Sale 2026-06-17 N/A 9.0 CRITICAL
The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functionality, which could be leveraged to escalate privileges or compromise any accounts they can coerce into observing the targeted files.
CVE-2022-40288 1 Phppointofsale 1 Php Point Of Sale 2026-06-17 N/A 9.0 CRITICAL
The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, which could be leveraged to escalate privileges within and compromise any account that views their user profile.
CVE-2022-40287 1 Phppointofsale 1 Php Point Of Sale 2026-06-17 N/A 9.0 CRITICAL
The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messaging functionality, leading to privilege escalation or a compromise of a targeted account.
CVE-2022-40257 1 Cert 1 Vince 2026-06-17 N/A 5.4 MEDIUM
An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field.
CVE-2022-40248 1 Cert 1 Vince 2026-06-17 N/A 5.4 MEDIUM
An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via form using the "Product Affected" field.
CVE-2022-40215 1 Tabs Project 1 Tabs 2026-06-17 N/A 3.4 LOW
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in Tabs plugin <= 3.7.1 at WordPress.
CVE-2022-40213 1 Gsplugins 1 Gs Testimonial Slider 2026-06-17 N/A 4.1 MEDIUM
Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in GS Testimonial Slider plugin <= 1.9.6 at WordPress.
CVE-2022-40211 1 Givewp 1 Givewp 2026-06-17 N/A 5.9 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GiveWP allows Stored XSS.This issue affects GiveWP: from n/a through 2.25.1.
CVE-2022-40209 1 Xylusthemes 1 Wp Smart Import 2026-06-17 N/A 6.1 MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Xylus Themes WP Smart Import plugin <= 1.0.2 on WordPress.
CVE-2022-40204 1 Digitalalertsystems 10 Dasdec I, Dasdec I Firmware, Dasdec Ii and 7 more 2026-06-17 N/A 4.1 MEDIUM
A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via the Host Header in undisclosed pages after login.
CVE-2022-40195 1 Loqate 1 Loqate 2026-06-17 N/A 4.8 MEDIUM
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PCA Predict plugin <= 1.0.3 at WordPress.