Vulnerabilities (CVE)

Filtered by CWE-79
Total 47482 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-37307 1 Open-xchange 1 Open-xchange Appsuite 2026-06-17 N/A 6.1 MEDIUM
OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature.
CVE-2022-37306 1 Open-xchange 1 Ox App Suite 2026-06-17 N/A 6.1 MEDIUM
OX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger.
CVE-2022-37254 1 Dolphinphp Project 1 Dolphinphp 2026-06-17 N/A 5.4 MEDIUM
DolphinPHP 1.5.1 is vulnerable to Cross Site Scripting (XSS) via Background - > System - > system function - > configuration management.
CVE-2022-37253 1 Crime Reporting System Project 1 Crime Reporting System 2026-06-17 N/A 5.4 MEDIUM
Persistent cross-site scripting (XSS) in Crime Reporting System 1.0 allows a remote attacker to introduce arbitary Javascript via manipulation of an unsanitized POST parameter
CVE-2022-37250 1 Craftcms 1 Craft Cms 2026-06-17 N/A 5.4 MEDIUM
Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.
CVE-2022-37248 1 Craftcms 1 Craft Cms 2026-06-17 N/A 5.4 MEDIUM
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.
CVE-2022-37247 1 Craftcms 1 Craft Cms 2026-06-17 N/A 5.4 MEDIUM
Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.
CVE-2022-37246 1 Craftcms 1 Craft Cms 2026-06-17 N/A 5.4 MEDIUM
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
CVE-2022-37245 1 Altn 1 Security Gateway For Email Servers 2026-06-17 N/A 5.4 MEDIUM
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint.
CVE-2022-37244 1 Altn 1 Security Gateway For Email Servers 2026-06-17 N/A 5.4 MEDIUM
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to inject malicious tag leads to IFRAME injection.
CVE-2022-37243 1 Altn 1 Security Gateway For Email Servers 2026-06-17 N/A 5.4 MEDIUM
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint.
CVE-2022-37241 1 Altn 1 Security Gateway For Email Servers 2026-06-17 N/A 5.4 MEDIUM
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoint.
CVE-2022-37239 1 Altn 1 Security Gateway For Email Servers 2026-06-17 N/A 5.4 MEDIUM
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint.
CVE-2022-37238 1 Altn 1 Security Gateway For Email Servers 2026-06-17 N/A 5.4 MEDIUM
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter.
CVE-2022-37183 1 Piwigo 1 Piwigo 2026-06-17 N/A 6.1 MEDIUM
Piwigo 12.3.0 is vulnerable to Cross Site Scripting (XSS) via /search/1940/created-monthly-list.
CVE-2022-37162 1 Claroline 1 Claroline 2026-06-17 N/A 5.4 MEDIUM
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event.
CVE-2022-37161 1 Claroline 1 Claroline 2026-06-17 N/A 6.1 MEDIUM
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
CVE-2022-37160 1 Claroline 1 Claroline 2026-06-17 N/A 5.4 MEDIUM
Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privileged user. By combining the XSS vulnerability present in several upload forms and a javascript request to the present API, it is possible to trigger the creation of a user with administrative rights by opening an SVG file as an administrator user.
CVE-2022-37153 1 Articatech 1 Artica Proxy 2026-06-17 N/A 6.1 MEDIUM
An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.
CVE-2022-37150 1 Online Diagnostic Lab Management System Project 1 Online Diagnostic Lab Management System 2026-06-17 N/A 5.4 MEDIUM
An issue was discovered in Online Diagnostic Lab Management System 1.0. There is a stored XSS vulnerability via firstname, address, middlename, lastname , gender, email, contact parameters.