Vulnerabilities (CVE)

Filtered by CWE-79
Total 47481 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-26246 1 Tms Project 1 Tms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
TMS v2.28.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /TMS/admin/setting/mail/createorupdate.
CVE-2022-26155 1 Cherwell 1 Cherwell Service Management 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. XSS can occur via a payload in the SAMLResponse parameter of the HTTP request body.
CVE-2022-26146 1 Tricentis 1 Qtest 2026-06-17 3.5 LOW 5.4 MEDIUM
Tricentis qTest before 10.4 allows stored XSS by an authenticated attacker.
CVE-2022-26144 1 Mantisbt 1 Mantisbt 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary code (if CSP allows it) in manage_plugin_page.php and manage_plugin_uninstall.php when a crafted plugin is installed.
CVE-2022-26114 1 Fortinet 1 Fortimail 2026-06-17 N/A 5.4 MEDIUM
An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail messages.
CVE-2022-26105 1 Sap 1 Netweaver Enterprise Portal 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the Network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
CVE-2022-26101 1 Sap 1 Fiori Launchpad 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Fiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2022-26088 1 Bmc 1 Remedy It Service Management Suite 2026-06-17 N/A 5.4 MEDIUM
An issue was discovered in BMC Remedy before 22.1. Email-based Incident Forwarding allows remote authenticated users to inject HTML (such as an SSRF payload) into the Activity Log by placing it in the To: field. This affects rendering that occurs upon a click in the "number of recipients" field. NOTE: the vendor's position is that "no real impact is demonstrated."
CVE-2022-25979 1 Jsuites 1 Jsuites 2026-06-17 N/A 5.4 MEDIUM
Versions of the package jsuites before 5.0.1 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization in the Editor() function.
CVE-2022-25978 1 Usememos 1 Memos 2026-06-17 N/A 5.4 MEDIUM
All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme.
CVE-2022-25929 1 Smoothiecharts 1 Smoothie Charts 2026-06-17 N/A 5.4 MEDIUM
The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.
CVE-2022-25875 1 Svelte 1 Svelte 2026-06-17 4.3 MEDIUM 5.4 MEDIUM
The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this vulnerability is possible via objects with a custom toString() function.
CVE-2022-25873 1 Vuetifyjs 1 Vuetify 2026-06-17 N/A 4.6 MEDIUM
The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.
CVE-2022-25869 1 Angularjs 1 Angularjs 2026-06-17 N/A 4.2 MEDIUM
All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.
CVE-2022-25854 1 Tagify Project 1 Tagify 2026-06-17 3.5 LOW 5.4 MEDIUM
This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input or text fields, and an attacker can pass a malicious placeholder value to it to fire the XSS payload.
CVE-2022-25849 1 Hyperdown Project 1 Hyperdown 2026-06-17 N/A 5.4 MEDIUM
The package joyqi/hyper-down from 0.0.0 are vulnerable to Cross-site Scripting (XSS) because the module of parse markdown does not filter the href attribute very well.
CVE-2022-25847 1 Serve-lite Project 1 Serve-lite 2026-06-17 N/A 5.4 MEDIUM
All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitization or output encoding.
CVE-2022-25802 1 Bestpractical 1 Request Tracker 2026-06-17 N/A 6.1 MEDIUM
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.
CVE-2022-25784 1 Secomea 18 Sitemanager 1129, Sitemanager 1129 Firmware, Sitemanager 1139 and 15 more 2026-06-17 3.5 LOW 9.1 CRITICAL
Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue affects: Secomea SiteManager all versions prior to 9.7.
CVE-2022-25781 1 Secomea 8 Gatemanager 4250, Gatemanager 4250 Firmware, Gatemanager 4260 and 5 more 2026-06-17 4.3 MEDIUM 4.2 MEDIUM
Cross-site Scripting (XSS) vulnerability in Web UI of Secomea GateManager allows phishing attacker to inject javascript or html into logged in user session.