Vulnerabilities (CVE)

Filtered by CWE-79
Total 47481 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-3866 1 Zulip 1 Zulip 2026-06-17 3.5 LOW 5.4 MEDIUM
Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6.
CVE-2021-3863 1 Snipeitapp 1 Snipe-it 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3862 1 Icecoder 1 Icecoder 2026-06-17 3.5 LOW 4.8 MEDIUM
icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3857 1 Chaskiq 1 Chaskiq 2026-06-17 3.5 LOW 5.4 MEDIUM
chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3853 1 Chaskiq 1 Chaskiq 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3841 1 Sylius 1 Sylius 2026-06-17 N/A 5.4 MEDIUM
sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of the user's browser.
CVE-2021-3834 1 Artica 1 Integria Ims 2026-06-17 4.3 MEDIUM 5.4 MEDIUM
Integria IMS in its 5.0.92 version does not filter correctly some fields related to the login.php file. An attacker could exploit this vulnerability in order to perform a cross-site scripting attack (XSS).
CVE-2021-3831 1 Gnuboard 1 Gnuboard5 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
gnuboard5 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3830 1 Btcpayserver 1 Btcpay Server 2026-06-17 3.5 LOW 5.4 MEDIUM
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3824 1 Openvpn 1 Openvpn Access Server 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.
CVE-2021-3816 1 Cacti 1 Cacti 2026-06-17 3.5 LOW 5.4 MEDIUM
Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a new group via "Copy" method at user_group_admin.php.
CVE-2021-3812 1 Pi-hole 1 Web Interface 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3811 1 Pi-hole 1 Web Interface 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3785 1 Yourls 1 Yourls 2026-06-17 3.5 LOW 5.4 MEDIUM
yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3783 1 Yourls 1 Yourls 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3780 1 Framasoft 1 Peertube 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
peertube is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3768 1 Bookstackapp 1 Bookstack 2026-06-17 3.5 LOW 5.4 MEDIUM
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3767 1 Bookstackapp 1 Bookstack 2026-06-17 3.5 LOW 5.4 MEDIUM
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3741 1 Chatwoot 1 Chatwoot 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.6. The vulnerability occurs when a user uploads an SVG file containing a malicious XSS payload in the profile settings. When the avatar is opened in a new page, the custom JavaScript code is executed, leading to potential security risks.
CVE-2021-3694 2 Debian, Ledgersmb 2 Debian Linux, Ledgersmb 2026-06-17 6.8 MEDIUM 8.2 HIGH
LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure.