Vulnerabilities (CVE)

Filtered by CWE-79
Total 47482 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-36405 1 Amcharts 1 Amcharts\ 2026-06-17 N/A 5.4 MEDIUM
Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in amCharts: Charts and Maps plugin <= 1.4 at WordPress.
CVE-2022-36390 1 Total-soft 1 Event Calendar 2026-06-17 N/A 4.1 MEDIUM
Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.
CVE-2022-36383 1 Webhelpagency 1 Wha Wordsearch 2026-06-17 N/A 5.4 MEDIUM
Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in WHA Word Search Puzzles game plugin <= 2.0.1 at WordPress.
CVE-2022-36378 1 Floating Div Project 1 Floating Div 2026-06-17 N/A 4.8 MEDIUM
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Floating Div plugin <= 3.0 at WordPress.
CVE-2022-36368 1 Ipfire 1 Ipfire 2026-06-17 N/A 4.8 MEDIUM
Multiple stored cross-site scripting vulnerabilities in the web user interface of IPFire versions prior to 2.27 allows a remote authenticated attacker with administrative privilege to inject an arbitrary script.
CVE-2022-36365 1 Webhelpagency 1 Wha Crossword 2026-06-17 N/A 5.4 MEDIUM
Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in WHA Crossword plugin <= 1.1.10 at WordPress.
CVE-2022-36357 1 Webpsilon 1 Ultimate Tables 2026-06-17 N/A 6.1 MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webpsilon ULTIMATE TABLES plugin <= 1.6.5 versions.
CVE-2022-36356 1 Culture Object Project 1 Culture Object 2026-06-17 N/A 4.8 MEDIUM
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Liam Gladdy / Thirty8 Digital Culture Object plugin <= 4.0.1 at WordPress.
CVE-2022-36355 1 Easy Org Chart Project 1 Easy Org Chart 2026-06-17 N/A 5.4 MEDIUM
Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Easy Org Chart plugin <= 3.1 at WordPress.
CVE-2022-36350 1 Pukiwiki 1 Pukiwiki 2026-06-17 N/A 5.4 MEDIUM
Stored cross-site scripting vulnerability in PukiWiki versions 1.3.1 to 1.5.3 allows a remote attacker to inject an arbitrary script via unspecified vectors.
CVE-2022-36347 1 Thealpinepress 1 Alpine Phototile For Pinterest 2026-06-17 N/A 4.8 MEDIUM
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alpine Press Alpine PhotoTile for Pinterest plugin <= 1.3.1 at WordPress.
CVE-2022-36343 1 Ideastocode 1 Enable Svg\, Webp \& Ico Upload 2026-06-17 N/A 3.4 LOW
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress.
CVE-2022-36341 1 As - Create Pinterest Pinboard Pages Project 1 As - Create Pinterest Pinboard Pages 2026-06-17 N/A 5.4 MEDIUM
Authenticated (subscriber+) plugin settings change leading to Stored Cross-Site Scripting (XSS) vulnerability in Akash soni's AS – Create Pinterest Pinboard Pages plugin <= 1.0 at WordPress.
CVE-2022-36311 1 Airspan 2 Airvelocity 1500, Airvelocity 1500 Firmware 2026-06-17 N/A 6.1 MEDIUM
Airspan AirVelocity 1500 prior to software version 15.18.00.2511 is vulnerable to injection leading to XSS in the SNMP community field in the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
CVE-2022-36305 1 Vestacp 1 Vesta Control Panel 2026-06-17 N/A 6.1 MEDIUM
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php.
CVE-2022-36304 1 Vestacp 1 Vesta Control Panel 2026-06-17 N/A 6.1 MEDIUM
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHandler.php.
CVE-2022-36303 1 Vestacp 1 Vesta Control Panel 2026-06-17 N/A 6.1 MEDIUM
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadHandler.php.
CVE-2022-36282 1 Search Exclude Project 1 Search Exclude 2026-06-17 N/A 4.8 MEDIUM
Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Roman Pronskiy's Search Exclude plugin <= 1.2.6 at WordPress.
CVE-2022-36277 1 Tcman 1 Gim 2026-06-17 N/A 6.5 MEDIUM
The 'sReferencia', 'sDescripcion', 'txtCodigo' and 'txtDescripcion' parameters, in the frmGestionStock.aspx and frmEditServicio.aspx files in TCMAN GIM v8.0.1, could allow an attacker to perform persistent XSS attacks.
CVE-2022-36266 1 Airspan 2 Airspot 5410, Airspot 5410 Firmware 2026-06-17 N/A 6.1 MEDIUM
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a stored XSS vulnerability. As the binary file /home/www/cgi-bin/login.cgi does not check if the user is authenticated, a malicious actor can craft a specific request on the login.cgi endpoint that contains a base32 encoded XSS payload that will be accepted and stored. A successful attack will results in the injection of malicious scripts into the user settings page.