Vulnerabilities (CVE)

Filtered by CWE-79
Total 47475 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-25918 1 Open-emr 1 Openemr 2026-06-17 3.5 LOW 4.8 MEDIUM
In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the TOTP Authentication method page. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.
CVE-2021-25917 1 Open-emr 1 Openemr 2026-06-17 3.5 LOW 4.8 MEDIUM
In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the U2F USB Device authentication method page. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.
CVE-2021-25894 1 Magnolia-cms 1 Magnolia Cms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the /magnoliaPublic/travel/members/login.html mgnlUserId parameter.
CVE-2021-25893 1 Magnolia-cms 1 Magnolia Cms 2026-06-17 3.5 LOW 5.4 MEDIUM
Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/.
CVE-2021-25838 1 Minthcm 1 Minthcm 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Import function in MintHCM RELEASE 3.0.8 allows an attacker to execute a cross-site scripting (XSS) payload in file-upload.
CVE-2021-25828 1 Emby 1 Emby 2026-06-17 N/A 6.1 MEDIUM
Emby Server versions < 4.6.0.50 is vulnerable to Cross Site Scripting (XSS) vulnerability via a crafted GET request to /web.
CVE-2021-25810 1 Mercusys 2 Mercury X18g, Mercury X18g Firmware 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters.
CVE-2021-25791 1 Online Doctor Appointment System Php Full Source Code Project 1 Online Doctor Appointment System Php Full Source Code 2026-06-17 3.5 LOW 5.4 MEDIUM
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.
CVE-2021-25790 1 House Rental And Property Listing Php Project 1 House Rental And Property Listing Php 2026-06-17 3.5 LOW 5.4 MEDIUM
Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.
CVE-2021-25785 1 Taogogo 1 Taocms 2026-06-17 3.5 LOW 4.8 MEDIUM
Taocms v2.5Beta5 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Management column.
CVE-2021-25773 1 Jetbrains 1 Teamcity 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.
CVE-2021-25656 1 Avaya 1 Aura Experience Portal 2026-06-17 3.5 LOW 5.3 MEDIUM
Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).
CVE-2021-25647 1 Testes-codigo 1 Testes De Codigo 2026-06-17 3.5 LOW 5.4 MEDIUM
Mobile application "Testes de Codigo" v11.3 and prior allows stored XSS by injecting a payload in the "feedback" message field causing it to be stored in the remote database and leading to its execution on client devices when loading the "feedback list", either by accessing the website directly or using the mobile application.
CVE-2021-25520 1 Samsung 1 Internet 2026-06-17 4.3 MEDIUM 5.9 MEDIUM
Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes in Samsung Internet.
CVE-2021-25327 1 Skyworthdigital 2 Rn510, Rn510 Firmware 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-urlfilter.asp. Missing CSRF protection in devices can lead to XSRF, as the above pages are vulnerable to cross-site scripting (XSS).
CVE-2021-25313 1 Suse 1 Rancher 2026-06-17 4.3 MEDIUM 7.1 HIGH
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute JavaScript via malicious links. This issue affects: SUSE Rancher Rancher versions prior to 2.5.6.
CVE-2021-25295 1 Opencats 1 Opencats 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.
CVE-2021-25278 1 Ftapi 1 Ftapi 2026-06-17 3.5 LOW 4.8 MEDIUM
FTAPI 4.0 through 4.10 allows XSS via an SVG document to the Background Image upload feature in the Submit Box Template Editor.
CVE-2021-25277 1 Ftapi 1 Ftapi 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
FTAPI 4.0 - 4.10 allows XSS via a crafted filename to the alternative text hover box in the file submission component.
CVE-2021-25273 1 Sophos 1 Unified Threat Management 2026-06-17 3.5 LOW 4.8 MEDIUM
Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.