Vulnerabilities (CVE)

Filtered by CWE-79
Total 47481 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-40882 1 Piwigo 1 Piwigo 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the location.
CVE-2021-40868 1 Cloudron 1 Cloudron 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
CVE-2021-40840 1 Liveconfig 1 Liveconfig 2026-06-17 3.5 LOW 5.4 MEDIUM
A Stored XSS issue exists in the admin/users user administration form in LiveConfig 2.12.2.
CVE-2021-40813 1 Element-it 1 Http Commander 2026-06-17 3.5 LOW 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in the "Zip content" feature in Element-IT HTTP Commander 3.1.9 allows remote authenticated users to inject arbitrary web script or HTML via filenames.
CVE-2021-40721 1 Adobe 1 Connect 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Adobe Connect version 11.2.3 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.
CVE-2021-40714 1 Adobe 1 Experience Manager 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the accesskey parameter. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser
CVE-2021-40711 1 Adobe 1 Experience Manager 2026-06-17 3.5 LOW 5.4 MEDIUM
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments. An authenticated attacker can send a malformed POST request to achieve arbitrary code execution. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
CVE-2021-40678 1 Piwigo 1 Piwigo 2026-06-17 3.5 LOW 5.4 MEDIUM
In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.
CVE-2021-40658 1 Textpattern 1 Textpattern 2026-06-17 3.5 LOW 4.8 MEDIUM
Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.
CVE-2021-40637 1 Os4ed 1 Opensis 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
OS4ED openSIS 8.0 is affected by cross-site scripting (XSS) in EmailCheckOthers.php. An attacker can inject JavaScript code to get the user's cookie and take over the working session of user.
CVE-2021-40610 1 Emlog Pro Project 1 Emlog Pro 2026-06-17 3.5 LOW 5.4 MEDIUM
Emlog Pro v 1.0.4 cross-site scripting (XSS) in Emlog Pro background management.
CVE-2021-40577 1 Online Enrollment Management System Project 1 Online Enrollment Management System 2026-06-17 3.5 LOW 5.4 MEDIUM
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 in the Add-Users page via the Name parameter.
CVE-2021-40555 1 Flatcore 1 Flatcore 2026-06-17 N/A 5.4 MEDIUM
Cross site scripting (XSS) vulnerability in flatCore-CMS 2.2.15 allows attackers to execute arbitrary code via description field on the new page creation form.
CVE-2021-40542 1 Os4ed 1 Opensis 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute JavaScript code through the link_url parameter in Ajax_url_encode.php.
CVE-2021-40541 1 Php-fusion 1 Phpfusion 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticated user can trigger XSS by appending "//" in the end of text.
CVE-2021-40517 1 Airangel 10 Hsmx-app-100, Hsmx-app-1000, Hsmx-app-1000 Firmware and 7 more 2026-06-17 3.5 LOW 5.4 MEDIUM
Airangel HSMX Gateway devices through 5.2.04 is vulnerable to stored Cross Site Scripting. XSS Payload is placed in the name column of the updates table using database access.
CVE-2021-40509 1 Jforum 1 Jforum 2026-06-17 3.5 LOW 5.4 MEDIUM
ViewCommon.java in JForum2 2.7.0 allows XSS via a user signature.
CVE-2021-40492 1 Gibbonedu 1 Gibbon 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPersonID, subpage, currentDate, or allStudents to index.php).
CVE-2021-40457 1 Microsoft 1 Dynamics 365 2026-06-17 4.3 MEDIUM 7.4 HIGH
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
CVE-2021-40377 1 Smartertools 1 Smartermail 2026-06-17 3.5 LOW 5.4 MEDIUM
SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The application fails to sanitize email content, thus allowing one to inject HTML and/or JavaScript into a page that will then be processed and stored by the application.