Vulnerabilities (CVE)

Filtered by CWE-79
Total 47385 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25090 1 Ecommerce-codeigniter-bootstrap Project 1 Ecommerce-codeigniter-bootstrap 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php.
CVE-2020-25089 1 Ecommerce-codeigniter-bootstrap Project 1 Ecommerce-codeigniter-bootstrap 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php.
CVE-2020-25088 1 Ecommerce-codeigniter-bootstrap Project 1 Ecommerce-codeigniter-bootstrap 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.
CVE-2020-25087 1 Ecommerce-codeigniter-bootstrap Project 1 Ecommerce-codeigniter-bootstrap 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/languages.php.
CVE-2020-25086 1 Ecommerce-codeigniter-bootstrap Project 1 Ecommerce-codeigniter-bootstrap 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php.
CVE-2020-25071 1 Niftypm 1 Nifty 2026-06-17 3.5 LOW 5.4 MEDIUM
Nifty Project Management Web Application 2020-08-26 allows XSS, via Add Task, that is rendered upon a Project Home visit. Note: It has been argued that this is not reproducible. "The original issue was that the task would be created and an alert would be shown on the screen. Now the task would be created, but the alert won't be executed as those attributes are now stripped.
CVE-2020-25033 1 Blubrry 1 Subscribe Sidebar 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Blubrry subscribe-sidebar (aka Subscribe Sidebar) plugin 1.3.1 for WordPress allows subscribe_sidebar.php&status= reflected XSS.
CVE-2020-24993 1 Cmswing 1 Cmswing 2026-06-17 3.5 LOW 5.4 MEDIUM
There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when visitors access the article module.
CVE-2020-24992 1 Cmswing 1 Cmswing 2026-06-17 3.5 LOW 5.4 MEDIUM
There is a cross site scripting vulnerability on CmsWing 1.3.7. This vulnerability (stored XSS) is triggered when an administrator accesses the content management module.
CVE-2020-24963 1 Appsbd 1 Best Support System 2026-06-17 3.5 LOW 5.4 MEDIUM
An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.
CVE-2020-24924 1 Elkarbackup 1 Elkarbackup 2026-06-17 3.5 LOW 5.4 MEDIUM
A Persistent Cross-site Scripting vulnerability is found in ElkarBackup v1.3.3, where an attacker can steal the user session cookie using this vulnerability present on Policies >> action >> Name Parameter
CVE-2020-24903 1 Cutesoft 1 Cute Editor 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVE-2020-24902 1 Quixplorer Project 1 Quixplorer 2026-06-17 4.3 MEDIUM 4.7 MEDIUM
Quixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVE-2020-24901 1 Krpano 1 Krpano 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remote js load in file viewer/krpano.html, parameter plugin[test].url.
CVE-2020-24900 1 Krpano 1 Krpano 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file /viewer/krpano.html, parameter xml.
CVE-2020-24897 1 Stiltsoft 1 Table Filter And Charts For Confluence Server 2026-06-17 3.5 LOW 8.9 HIGH
The Table Filter and Charts for Confluence Server app before 5.3.25 (for Atlassian Confluence) allow remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) through the provided Markdown markup to the "Table from CSV" macro.
CVE-2020-24872 1 Lepton-cms 1 Leptoncms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitrary code.
CVE-2020-24861 1 Get-simple 1 Getsimple Cms 2026-06-17 3.5 LOW 5.4 MEDIUM
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page
CVE-2020-24860 1 Cmsmadesimple 1 Cms Made Simple 2026-06-17 3.5 LOW 5.4 MEDIUM
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.
CVE-2020-24857 1 Inex 1 Ixp Manager 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerabilty found in IXPManager v.5.6.0 allows attackers to excute arbitrary code via the looking glass component.