Vulnerabilities (CVE)

Filtered by CWE-79
Total 47481 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-23988 1 Westguardsolutions 1 Ws Form 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission
CVE-2022-23987 1 Westguardsolutions 1 Ws Form 2026-06-17 3.5 LOW 4.8 MEDIUM
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2022-23980 1 Yet Another Stars Rating Project 1 Yet Another Stars Rating 2026-06-17 4.3 MEDIUM 4.7 MEDIUM
Cross-Site Scripting (XSS) vulnerability discovered in Yasr – Yet Another Stars Rating WordPress plugin (versions <= 2.9.9), vulnerable at parameter 'source'.
CVE-2022-23979 1 Etoilewebdesign 1 Ultimate Reviews 2026-06-17 3.5 LOW 4.8 MEDIUM
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).
CVE-2022-23961 2026-06-17 N/A 6.1 MEDIUM
In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by unauthenticated remote attackers to target users of the monitoring interface.
CVE-2022-23916 1 Appleple 1 A-blog Cms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. This vulnerability is different from CVE-2022-24374.
CVE-2022-23912 1 Accesspressthemes 1 Ap Custom Testimonial 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outputting it back in an attribute, leading to a Reflected cross-Site Scripting
CVE-2022-23907 1 Cmsmadesimple 1 Cms Made Simple 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.
CVE-2022-23903 1 Pearadmin 1 Pear Admin Think 2026-06-17 3.5 LOW 5.4 MEDIUM
A Cross Site Scripting (XSS) vulnerability exists in pearadmin pear-admin-think <=5.0.6, which allows a login account to access arbitrary functions and cause stored XSS through a fake User-Agent.
CVE-2022-23896 1 Admidio 1 Admidio 2026-06-17 3.5 LOW 5.4 MEDIUM
Admidio 4.1.2 version is affected by stored cross-site scripting (XSS).
CVE-2022-23872 1 Emlog 1 Emlog 2026-06-17 3.5 LOW 4.8 MEDIUM
Emlog pro v1.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /admin/configure.php via the parameter footer_info.
CVE-2022-23871 1 Gibbonedu 1 Gibbon 2026-06-17 3.5 LOW 5.4 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of Gibbon CMS v22.0.01 allow attackers to execute arbitrary web scripts or HTML via a crafted payload insterted into the name, category, description parameters.
CVE-2022-23861 1 Ysoft 1 Safeq 2026-06-17 N/A 5.4 MEDIUM
Multiple Stored Cross-Site Scripting vulnerabilities were discovered in Y Soft SAFEQ 6 Build 53. Multiple fields in the YSoft SafeQ web application can be used to inject malicious inputs that, due to a lack of output sanitization, result in the execution of arbitrary JS code. These fields can be leveraged to perform XSS attacks on legitimate users accessing the SafeQ web interface.
CVE-2022-23808 1 Phpmyadmin 1 Phpmyadmin 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.
CVE-2022-23801 1 Joomla 1 Joomla\! 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media.
CVE-2022-23800 1 Joomla 1 Joomla\! 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components.
CVE-2022-23796 1 Joomla 1 Joomla\! 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fields.
CVE-2022-23791 1 Firmanet 1 Customer Relation Manager 2026-06-17 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firmanet Software and Technology Customer Relation Manager allows Cross-Site Scripting (XSS). This issue affects Customer Relation Manager: before 2022.03.13.
CVE-2022-23790 1 Firmanet 1 Technology Customer Relation Manager 2026-06-17 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firmanet Software and Technology Customer Relation Manager allows Cross-Site Scripting (XSS). This issue affects Customer Relation Manager: before 2022.03.13.
CVE-2022-23733 1 Github 1 Enterprise Server 2026-06-17 N/A 5.4 MEDIUM
A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes. This injection was blocked by Github's Content Security Policy (CSP). This vulnerability affected all versions of GitHub Enterprise Server prior to 3.6 and was fixed in versions 3.3.11, 3.4.6 and 3.5.3. This vulnerability was reported via the GitHub Bug Bounty program.