Vulnerabilities (CVE)

Filtered by CWE-79
Total 47486 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-36772 1 Zohocorp 1 Manageengine Admanager Plus 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine ADManager Plus before 7110 allows stored XSS.
CVE-2021-36771 1 Zohocorp 1 Manageengine Admanager Plus 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS.
CVE-2021-36760 1 Wso2 4 Api Manager, Identity Server, Identity Server As Key Manager and 1 more 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback parameter modifying the URL that precedes the callback parameter. Once the username or password reset procedure is completed, the JavaScript code will be executed. (recoverpassword.do also has an open redirect issue for a similar reason.)
CVE-2021-36755 1 Cgm-remote-monitor Project 1 Cgm-remote-monitor 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Nightscout Web Monitor (aka cgm-remote-monitor) 14.2.2 allows XSS via a crafted X-Forwarded-For header.
CVE-2021-36747 1 Blackboard 1 Blackboard Learn 2026-06-17 3.5 LOW 5.4 MEDIUM
Blackboard Learn through 9.1 allows XSS by an authenticated user via the Feedback to Learner form.
CVE-2021-36746 1 Blackboard 1 Blackboard Learn 2026-06-17 3.5 LOW 5.4 MEDIUM
Blackboard Learn through 9.1 allows XSS by an authenticated user via the Assignment Instructions HTML editor.
CVE-2021-36739 1 Apache 1 Pluto 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) attacks.
CVE-2021-36738 1 Apache 1 Pluto 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the applicant-mvcbean-cdi-jsp-portlet.war artifact
CVE-2021-36737 1 Apache 1 Pluto 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the v3-demo-portlet.war artifact
CVE-2021-36720 1 Pineapp 1 Mail Secure 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
PineApp - Mail Secure - Attacker sending a request to :/blocking.php?url=<script>alert(1)</script> and stealing cookies .
CVE-2021-36713 1 Sprymedia 1 Datatables 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in the DataTables plug-in 1.9.2 for jQuery allows attackers to run arbitrary code via the sBaseName parameter to function _fnCreateCookie. NOTE: 1.9.2 is a version from 2012.
CVE-2021-36703 1 Htmly 1 Htmly 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability. It allows remote attackers to send an authenticated post HTTP request to admin/config and inject arbitrary web script or HTML through a special website name.
CVE-2021-36702 1 Htmly 1 Htmly 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability. It allows remote attackers to send authenticated post-http requests to add / content and inject arbitrary web scripts or HTML through special content.
CVE-2021-36696 1 Deskpro 1 Deskpro 2026-06-17 3.5 LOW 5.4 MEDIUM
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in social media links on a user profile due to lack of input validation.
CVE-2021-36695 1 Deskpro 1 Deskpro 2026-06-17 3.5 LOW 5.4 MEDIUM
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file feature on a manager profile due to lack of input validation.
CVE-2021-36686 1 Ymfe 1 Yapi 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api edit page.
CVE-2021-36654 1 Cmsuno Project 1 Cmsuno 2026-06-17 3.5 LOW 5.4 MEDIUM
CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme.
CVE-2021-36646 1 Kodcloud 1 Kodexplorer 2026-06-17 N/A 6.1 MEDIUM
A Cross Site Scrtpting (XSS) vulnerability in KodExplorer 4.45 allows remote attackers to run arbitrary code via /index.php page.
CVE-2021-36609 1 Webtareas Project 1 Webtareas 2026-06-17 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /linkedcontent/editfolder.php.
CVE-2021-36608 1 Webtareas Project 1 Webtareas 2026-06-17 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /projects/editproject.php.