Vulnerabilities (CVE)

Filtered by CWE-79
Total 47481 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-28367 1 Antisamy Project 1 Antisamy 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content.
CVE-2022-28364 1 Reprisesoftware 1 Reprise License Manager 2026-06-17 3.5 LOW 5.4 MEDIUM
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/rlmswitchr_process file parameter via GET. Authentication is required.
CVE-2022-28363 1 Reprisesoftware 1 Reprise License Manager 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET. No authentication is required.
CVE-2022-28354 1 Mybb 1 Active Threads 2026-06-17 N/A 6.1 MEDIUM
In the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a time period.
CVE-2022-28353 1 External Redirect Warning Project 1 External Redirect Warning 2026-06-17 N/A 6.1 MEDIUM
In the External Redirect Warning Plugin 1.3 for MyBB, the redirect URL (aka external.php?url=) is vulnerable to XSS.
CVE-2022-28290 1 Welaunch 1 Wordpress Country Selector 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries to access the country selector page with the specified payload as a part of the HTTP request
CVE-2022-28222 1 Cleantalk 1 Antispam 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Users.php`
CVE-2022-28221 1 Cleantalk 1 Antispam 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Comments.php`
CVE-2022-28216 1 Sap 1 Businessobjects Business Intelligence Platform 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
SAP BusinessObjects Business Intelligence Platform (BI Workspace) - version 420, is susceptible to a Cross-Site Scripting attack by an unauthenticated attacker due to improper sanitization of the user inputs on the network. On successful exploitation, an attacker can access certain reports causing a limited impact on confidentiality of the application data.
CVE-2022-28202 3 Debian, Fedoraproject, Mediawiki 3 Debian Linux, Fedora, Mediawiki 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.
CVE-2022-28172 1 Hikvision 22 Ds-a71024, Ds-a71024 Firmware, Ds-a71048 and 19 more 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to XSS attack by sending messages with malicious commands to the affected device.
CVE-2022-28159 1 Jenkins 1 Tests Selector 2026-06-17 3.5 LOW 5.4 MEDIUM
Jenkins Tests Selector Plugin 1.3.3 and earlier does not escape the Properties File Path option for Choosing Tests parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVE-2022-28153 1 Jenkins 1 Sitemonitor 2026-06-17 3.5 LOW 5.4 MEDIUM
Jenkins SiteMonitor Plugin 0.6 and earlier does not escape URLs of sites to monitor in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVE-2022-28149 1 Jenkins 1 Job And Node Ownership 2026-06-17 3.5 LOW 5.4 MEDIUM
Jenkins Job and Node ownership Plugin 0.13.0 and earlier does not escape the names of the secondary owners, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVE-2022-28145 1 Jenkins 1 Continuous Integration With Toad Edge 2026-06-17 3.5 LOW 5.4 MEDIUM
Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier does not apply Content-Security-Policy headers to report files it serves, resulting in a stored cross-site scripting (XSS) exploitable by attackers with Item/Configure permission or otherwise able to control report contents.
CVE-2022-28133 1 Jenkins 1 Bitbucket Server Integration 2026-06-17 3.5 LOW 5.4 MEDIUM
Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not limit URL schemes for callback URLs on OAuth consumers, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create BitBucket Server consumers.
CVE-2022-28101 1 Lyonbros 1 Turtl 2026-06-17 6.0 MEDIUM 9.0 CRITICAL
Turtlapp Turtle Note v0.7.2.6 does not filter the <meta> tag during markdown parsing, allowing attackers to execute HTML injection.
CVE-2022-28081 1 Ar-php 1 Arphp 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in the component Query.php of arPHP v3.6.0 allows attackers to execute arbitrary web scripts.
CVE-2022-28074 1 Fit2cloud 1 Halo 2026-06-17 3.5 LOW 4.8 MEDIUM
Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/tools.
CVE-2022-28051 1 Seeddms 1 Seeddms 2026-06-17 3.5 LOW 5.4 MEDIUM
The "Add category" functionality inside the "Global Keywords" menu in "SeedDMS" version 6.0.18 and 5.1.25, is prone to stored XSS which allows an attacker to inject malicious javascript code.