Vulnerabilities (CVE)

Filtered by CWE-79
Total 47482 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-31648 1 Talend 1 Administration Center 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Talend Administration Center is vulnerable to a reflected Cross-Site Scripting (XSS) issue in the SSO login endpoint. The issue is fixed for versions 8.0.x in TPS-5233, for versions 7.3.x in TPS-5324, and for versions 7.2.x in TPS-5235. Earlier versions of Talend Administration Center may also be impacted; users are encouraged to update to a supported version.
CVE-2022-31498 1 Librehealth 1 Librehealth Ehr 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS.
CVE-2022-31497 1 Librehealth 1 Librehealth Ehr 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS.
CVE-2022-31495 1 Librehealth 1 Librehealth Ehr 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS.
CVE-2022-31494 1 Librehealth 1 Librehealth Ehr 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS.
CVE-2022-31493 1 Librehealth 1 Librehealth Ehr 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS.
CVE-2022-31492 1 Librehealth 1 Librehealth Ehr 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username.
CVE-2022-31470 1 Axigen 1 Axigen Mobile Webmail 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12 and 10.3.x before 10.3.3.47 allows attackers to run arbitrary Javascript code that, using an active end-user session (for a logged-in user), can access and retrieve mailbox content.
CVE-2022-31469 1 Open-xchange 1 Open-xchange Appsuite 2026-06-17 N/A 6.1 MEDIUM
OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.
CVE-2022-31468 1 Open-xchange 1 Ox App Suite 2026-06-17 N/A 6.1 MEDIUM
OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.
CVE-2022-31456 1 Truedesk 1 Truedesk 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Truedesk v1.2.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the team name parameter.
CVE-2022-31455 1 Truedesk 1 Truedesk 2026-06-17 N/A 6.1 MEDIUM
* A cross-site scripting (XSS) vulnerability in Truedesk v1.2.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a user chat box.
CVE-2022-31454 1 Yiiframework 1 Yii 2026-06-17 N/A 6.1 MEDIUM
Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books. NOTE: this is disputed by the vendor because the cve-2022-31454-8e8555c31fd3 page does not describe why /books has a relationship to Yii 2.
CVE-2022-31403 1 Combodo 1 Itop 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/pages/ajax.render.php.
CVE-2022-31402 1 Combodo 1 Itop 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.
CVE-2022-31400 1 Helpdeskz 1 Helpdeskz 2026-06-17 3.5 LOW 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.
CVE-2022-31398 1 Helpdeskz 1 Helpdeskz 2026-06-17 3.5 LOW 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.
CVE-2022-31373 1 Contec 2 Sv-cpt-mc310, Sv-cpt-mc310 Firmware 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiConf.php.
CVE-2022-31303 1 Maccms 1 Maccms 2026-06-17 3.5 LOW 5.4 MEDIUM
maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
CVE-2022-31302 1 Maccms 1 Maccms 2026-06-17 3.5 LOW 5.4 MEDIUM
maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.