Total
47481 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-40882 | 1 Piwigo | 1 Piwigo | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the location. | |||||
| CVE-2021-40868 | 1 Cloudron | 1 Cloudron | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS. | |||||
| CVE-2021-40840 | 1 Liveconfig | 1 Liveconfig | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| A Stored XSS issue exists in the admin/users user administration form in LiveConfig 2.12.2. | |||||
| CVE-2021-40813 | 1 Element-it | 1 Http Commander | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the "Zip content" feature in Element-IT HTTP Commander 3.1.9 allows remote authenticated users to inject arbitrary web script or HTML via filenames. | |||||
| CVE-2021-40721 | 1 Adobe | 1 Connect | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Adobe Connect version 11.2.3 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. | |||||
| CVE-2021-40714 | 1 Adobe | 1 Experience Manager | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the accesskey parameter. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser | |||||
| CVE-2021-40711 | 1 Adobe | 1 Experience Manager | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments. An authenticated attacker can send a malformed POST request to achieve arbitrary code execution. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | |||||
| CVE-2021-40678 | 1 Piwigo | 1 Piwigo | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit. | |||||
| CVE-2021-40658 | 1 Textpattern | 1 Textpattern | 2026-06-17 | 3.5 LOW | 4.8 MEDIUM |
| Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”. | |||||
| CVE-2021-40637 | 1 Os4ed | 1 Opensis | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| OS4ED openSIS 8.0 is affected by cross-site scripting (XSS) in EmailCheckOthers.php. An attacker can inject JavaScript code to get the user's cookie and take over the working session of user. | |||||
| CVE-2021-40610 | 1 Emlog Pro Project | 1 Emlog Pro | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Emlog Pro v 1.0.4 cross-site scripting (XSS) in Emlog Pro background management. | |||||
| CVE-2021-40577 | 1 Online Enrollment Management System Project | 1 Online Enrollment Management System | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 in the Add-Users page via the Name parameter. | |||||
| CVE-2021-40555 | 1 Flatcore | 1 Flatcore | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross site scripting (XSS) vulnerability in flatCore-CMS 2.2.15 allows attackers to execute arbitrary code via description field on the new page creation form. | |||||
| CVE-2021-40542 | 1 Os4ed | 1 Opensis | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute JavaScript code through the link_url parameter in Ajax_url_encode.php. | |||||
| CVE-2021-40541 | 1 Php-fusion | 1 Phpfusion | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticated user can trigger XSS by appending "//" in the end of text. | |||||
| CVE-2021-40517 | 1 Airangel | 10 Hsmx-app-100, Hsmx-app-1000, Hsmx-app-1000 Firmware and 7 more | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| Airangel HSMX Gateway devices through 5.2.04 is vulnerable to stored Cross Site Scripting. XSS Payload is placed in the name column of the updates table using database access. | |||||
| CVE-2021-40509 | 1 Jforum | 1 Jforum | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| ViewCommon.java in JForum2 2.7.0 allows XSS via a user signature. | |||||
| CVE-2021-40492 | 1 Gibbonedu | 1 Gibbon | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPersonID, subpage, currentDate, or allStudents to index.php). | |||||
| CVE-2021-40457 | 1 Microsoft | 1 Dynamics 365 | 2026-06-17 | 4.3 MEDIUM | 7.4 HIGH |
| Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability | |||||
| CVE-2021-40377 | 1 Smartertools | 1 Smartermail | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The application fails to sanitize email content, thus allowing one to inject HTML and/or JavaScript into a page that will then be processed and stored by the application. | |||||
