Vulnerabilities (CVE)

Filtered by CWE-79
Total 47482 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-37430 1 Silverstripe 1 Framework 2026-06-17 N/A 5.4 MEDIUM
Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).
CVE-2022-37429 1 Silverstripe 1 Framework 2026-06-17 N/A 5.4 MEDIUM
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters.
CVE-2022-37421 1 Silverstripe 1 Silverstripe 2026-06-17 N/A 5.4 MEDIUM
Silverstripe silverstripe/cms through 4.11.0 allows XSS.
CVE-2022-37412 1 Better Delete Revision Project 1 Better Delete Revision 2026-06-17 N/A 4.8 MEDIUM
Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Galerio & Urda's Better Delete Revision plugin <= 1.6.1 at WordPress.
CVE-2022-37407 1 Wpchill 1 Gallery Photoblocks 2026-06-17 N/A 4.1 MEDIUM
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.
CVE-2022-37406 1 Ricoh 2 Aficio Sp 4210n, Aficio Sp 4210n Firmware 2026-06-17 N/A 4.8 MEDIUM
Cross-site scripting vulnerability in Aficio SP 4210N firmware versions prior to Web Support 1.05 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script.
CVE-2022-37404 1 Add2fav Project 1 Add2fav 2026-06-17 N/A 4.8 MEDIUM
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christian Salazar's add2fav plugin <= 1.0 at WordPress.
CVE-2022-37403 1 Add User Role Project 1 Add User Role 2026-06-17 N/A 4.8 MEDIUM
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nikhil Vaghela's Add User Role plugin <= 0.0.1 at WordPress.
CVE-2022-37402 1 Afsanalytics 1 Afs Analytics 2026-06-17 N/A 4.8 MEDIUM
Stored Cross-site Scripting (XSS) vulnerability in AFS Analytics plugin <= 4.18 versions.
CVE-2022-37342 1 Add Shortcodes Actions And Filters Project 1 Add Shortcodes Actions And Filters 2026-06-17 N/A 4.8 MEDIUM
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability Add Shortcodes Actions And Filters plugin <= 2.0.9 at WordPress.
CVE-2022-37339 1 Fullworksplugins 1 Meet My Team 2026-06-17 N/A 4.1 MEDIUM
Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Meet My Team plugin <= 2.0.5 at WordPress.
CVE-2022-37338 1 Blossomthemes 1 Blossom Recipe Maker 2026-06-17 N/A 4.1 MEDIUM
Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Blossom Recipe Maker plugin <= 1.0.7 at WordPress.
CVE-2022-37335 1 Webhelpagency 1 Word Search Puzzles 2026-06-17 N/A 4.8 MEDIUM
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in WHA's Word Search Puzzles game plugin <= 2.0.1 at WordPress.
CVE-2022-37330 1 Webhelpagency 1 Wha Crossword 2026-06-17 N/A 5.4 MEDIUM
Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA Crossword plugin <= 1.1.10 at WordPress.
CVE-2022-37328 1 Themesawesome 1 Timeline Awesome 2026-06-17 N/A 3.4 LOW
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in Themes Awesome History Timeline plugin <= 1.0.5 at WordPress.
CVE-2022-37318 1 Rsa 1 Archer 2026-06-17 N/A 7.0 HIGH
Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application. This code is then reflected to the victim and gets executed by the web browser in the context of the vulnerable web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.
CVE-2022-37317 1 Rsa 1 Archer 2026-06-17 N/A 7.6 HIGH
Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious code in the context of the web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.
CVE-2022-37310 1 Open-xchange 1 Open-xchange Appsuite 2026-06-17 N/A 6.1 MEDIUM
OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.
CVE-2022-37309 1 Open-xchange 1 Open-xchange Appsuite 2026-06-17 N/A 6.1 MEDIUM
OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.
CVE-2022-37308 1 Open-xchange 1 Open-xchange Appsuite 2026-06-17 N/A 6.1 MEDIUM
OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.