Vulnerabilities (CVE)

Filtered by CWE-79
Total 47243 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-45992 1 Commscope 1 Ruckus Cloudpath Enrollment System 2026-07-09 N/A 9.6 CRITICAL
A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.
CVE-2023-43232 1 Dedebiz 1 Dedebiz 2026-07-09 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter.
CVE-2023-42426 1 Froala 1 Froala Editor 2026-07-09 N/A 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert link' parameter in the 'Insert Image' component.
CVE-2023-42399 1 Xdsoft 1 Joditeditor 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensitive information via the rich text editor component.
CVE-2023-41453 1 Phpkobo 1 Ajaxnewsticker 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the cmd parameter in the index.php component.
CVE-2023-41451 1 Phpkobo 1 Ajaxnewsticker 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component.
CVE-2023-41448 1 Phpkobo 1 Ajaxnewsticker 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the ID parameter in the index.php component.
CVE-2023-41447 1 Phpkobo 1 Ajaxnewsticker 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the subcmd parameter in the index.php component.
CVE-2023-41446 1 Phpkobo 1 Ajaxnewsticker 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php component.
CVE-2023-41445 1 Phpkobo 1 Ajaxnewsticker 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the index.php component.
CVE-2023-41425 1 Wondercms 1 Wondercms 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script uploaded to the installModule component.
CVE-2023-41013 1 Icewarp 1 Icewarp 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) in Webmail Calendar in IceWarp 10.3.1 allows remote attackers to inject arbitrary web script or HTML via the "p4" field.
CVE-2023-40986 1 Webmin 1 Webmin 2026-07-09 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Usermin Configuration function of Webmin v2.100 allows attackers to execute arbitrary web sripts or HTML via a crafted payload injected into the Custom field.
CVE-2023-40985 1 Webmin 1 Webmin 2026-07-09 N/A 5.4 MEDIUM
An issue was discovered in Webmin 2.100. The File Manager functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's browser when any file is searched/replaced.
CVE-2023-40984 1 Webmin 1 Webmin 2026-07-09 N/A 5.4 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Replace in Results file.
CVE-2023-40983 1 Webmin 1 Webmin 2026-07-09 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Find in Results file.
CVE-2023-40982 1 Webmin 1 Webmin 2026-07-09 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Webmin v2.100 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cloned module name parameter.
CVE-2023-40932 1 Nagios 1 Nagios Xi 2026-07-09 N/A 5.4 MEDIUM
A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.
CVE-2023-38888 1 Dolibarr 1 Dolibarr Erp\/crm 2026-07-09 N/A 9.6 CRITICAL
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
CVE-2023-37798 1 Vanderbilt 1 Redcap 2026-07-09 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.35 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the project title parameter.