Total
47245 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-50765 | 1 Koha | 1 Koha | 2026-07-05 | N/A | 6.1 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the restriction type label (display_text field). | |||||
| CVE-2026-36906 | 2026-07-05 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in iotgateway v.3.0.1 allows a remote attacker to execute arbitrary code via the Log Record Function | |||||
| CVE-2026-36388 | 2026-07-05 | N/A | 5.4 MEDIUM | ||
| A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to inject a malicious script payload into the User Name parameter, which is stored in the application and later rendered in the doctor s interface. | |||||
| CVE-2026-36358 | 2026-07-05 | N/A | 5.4 MEDIUM | ||
| Cross Site Scripting vulnerability in Juzaweb CMS v.5.0.0 allows a remote attacker via execute arbitrary code via a crafted script to the Add Banner Ads function | |||||
| CVE-2026-31313 | 1 Feehi | 1 Feehi Cms | 2026-07-05 | N/A | 5.4 MEDIUM |
| An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Content field. | |||||
| CVE-2026-30082 | 2026-07-05 | N/A | 6.1 MEDIUM | ||
| Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngEstate Server v11.14.0 allow attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the About application, What's news, or Release note parameters. | |||||
| CVE-2025-70545 | 1 Belden | 2 Ppc 2k05x, Ppc 2k05x Firmware | 2026-07-05 | N/A | 6.1 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X router running firmware v1.1.9_206L. The Common Gateway Interface (CGI) component improperly handles user-supplied input, allowing a remote, unauthenticated attacker to inject arbitrary JavaScript that is persistently stored and executed when the affected interface is accessed. | |||||
| CVE-2025-70365 | 2026-07-05 | N/A | 5.4 MEDIUM | ||
| A stored cross-site scripting (XSS) vulnerability exists in Kiamo before 8.4 due to improper output encoding of user-supplied input in administrative interfaces. An authenticated administrative user can inject arbitrary JavaScript code that is executed in the browser of users viewing the affected pages. NOTE: the Supplier's position is that a fix for this had already been released for the 8.3.1 branch before the CVE Record was published. | |||||
| CVE-2025-67291 | 1 Dotnetfoundation | 1 Piranha Cms | 2026-07-05 | N/A | 6.1 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field. | |||||
| CVE-2025-67290 | 1 Dotnetfoundation | 1 Piranha Cms | 2026-07-05 | N/A | 6.1 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Excerpt field. | |||||
| CVE-2025-65676 | 1 Classroomio | 1 Classroomio | 2026-07-05 | N/A | 5.4 MEDIUM |
| Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG cover images. | |||||
| CVE-2025-65675 | 1 Classroomio | 1 Classroomio | 2026-07-05 | N/A | 5.4 MEDIUM |
| Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG profile pictures. | |||||
| CVE-2025-65622 | 1 Snipeitapp | 1 Snipe-it | 2026-07-05 | N/A | 5.4 MEDIUM |
| Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session. | |||||
| CVE-2025-65621 | 1 Snipeitapp | 1 Snipe-it | 2026-07-05 | N/A | 5.4 MEDIUM |
| Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation. | |||||
| CVE-2025-64054 | 1 Fanvil | 2 X210, X210 Firmware | 2026-07-05 | N/A | 9.6 CRITICAL |
| A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint. | |||||
| CVE-2025-64048 | 1 Yccms | 1 Yccms | 2026-07-05 | N/A | 6.1 MEDIUM |
| YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulnerability exists in the add() and getPost() functions within the ArticleAction.class.php file due to improper neutralization of user input in the article title field. | |||||
| CVE-2025-64047 | 1 Openrapid | 1 Rapidcms | 2026-07-05 | N/A | 6.1 MEDIUM |
| OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php. | |||||
| CVE-2025-64046 | 1 Openrapid | 1 Rapidcms | 2026-07-05 | N/A | 6.1 MEDIUM |
| OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php. | |||||
| CVE-2025-63260 | 1 Syncfusion | 1 Syncfusion | 2026-07-05 | N/A | 5.4 MEDIUM |
| SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message. | |||||
| CVE-2025-61078 | 1 Phpipam | 1 Phpipam | 2026-07-05 | N/A | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the instructions parameter for the /app/admin/instructions/edit-result.php endpoint. | |||||
