Vulnerabilities (CVE)

Filtered by CWE-79
Total 47481 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-26673 1 Asus 2 Rt-ax88u, Rt-ax88u Firmware 2026-06-17 3.5 LOW 5.4 MEDIUM
ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform Stored Cross-Site Scripting (XSS) attacks.
CVE-2022-26624 1 Ecommerce Codeigniter Bootstrap Project 1 Ecommerce Codeigniter Bootstrap 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php.
CVE-2022-26616 1 Public Knowledge Project 1 Open Journal Systems 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers.
CVE-2022-26615 1 College Website Content Management System Project 1 College Website Content Management System 2026-06-17 3.5 LOW 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields.
CVE-2022-26573 1 Maccms 1 Maccms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the select and input parameters.
CVE-2022-26565 1 Totaljs 1 Content Management System 2026-06-17 3.5 LOW 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when creating a new page.
CVE-2022-26564 1 Digitaldruid 1 Hoteldruid 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php.
CVE-2022-26555 1 Eova 1 Eova 2026-06-17 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Add a Button function of Eova v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the button name text box.
CVE-2022-26533 1 Alistgo 1 Alist 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Alist v2.1.0 and below was discovered to contain a cross-site scripting (XSS) vulnerability via /i/:data/ipa.plist.
CVE-2022-26497 1 Bigbluebutton 1 Greenlight 2026-06-17 3.5 LOW 5.4 MEDIUM
BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of the victim in the "Share room access" dialog if the victim has shared access to the particular room with the attacker previously.
CVE-2022-26494 1 Primekey 1 Signserver 2026-06-17 3.5 LOW 4.8 MEDIUM
An XSS was identified in the Admin Web interface of PrimeKey SignServer before 5.8.1. JavaScript code must be used in a worker name before a Generate CSR request. Only an administrator can update a worker name.
CVE-2022-26483 1 Veritas 1 Infoscale Operations Manager 2026-06-17 3.5 LOW 4.8 MEDIUM
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. A reflected cross-site scripting (XSS) vulnerability in admin/cgi-bin/listdir.pl allows authenticated remote administrators to inject arbitrary web script or HTML into an HTTP GET parameter (which reflect the user input without sanitization).
CVE-2022-26375 1 Abpressoptimizer 1 Ab Press Optimizer 2026-06-17 N/A 4.8 MEDIUM
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mammothology AB Press Optimizer plugin <= 1.1.1 on WordPress.
CVE-2022-26332 1 Cipi 1 Cipi 2026-06-17 3.5 LOW 5.4 MEDIUM
Cipi 3.1.15 allows Add Server stored XSS via the /api/servers name field.
CVE-2022-26331 1 Microfocus 1 Arcsight Logger 2026-06-17 N/A 6.1 MEDIUM
Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects: Micro Focus ArcSight Logger versions prior to v7.2.2 version and prior versions.
CVE-2022-26328 2026-06-17 N/A N/A
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText Performance Center on Windows allows Cross-Site Scripting (XSS).This issue affects Performance Center: 12.63.
CVE-2022-26325 1 Microfocus 1 Netiq Access Manager 2026-06-17 4.3 MEDIUM 2.9 LOW
Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.2
CVE-2022-26324 1 Microfocus 1 Imanager 2026-06-17 N/A 7.6 HIGH
Possible XSS in iManager URL for access Component has been discovered in OpenTextâ„¢ iManager 3.2.6.0000.
CVE-2022-26295 1 Online Project Time Management System Project 1 Online Project Time Management System 2026-06-17 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in /ptms/?page=user of Online Project Time Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user name field.
CVE-2022-26255 1 Clash Project 1 Clash 2026-06-17 7.5 HIGH 9.8 CRITICAL
Clash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxies name column.