Vulnerabilities (CVE)

Filtered by CWE-79
Total 47246 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-52206 1 Ispconfig 1 Ispconfig 2026-07-05 N/A 4.7 MEDIUM
ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.
CVE-2025-51965 2026-07-05 N/A 6.1 MEDIUM
OURPHP thru 8.6.1 is vulnerable to Cross-Site Scripting (XSS) via the "Name" field of the "Complete Profile" functionality under the "My User Center" page, which can be accessed after registering through the front-end interface.
CVE-2025-52169 2026-07-05 N/A 7.1 HIGH
agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.
CVE-2025-51857 2026-07-05 N/A 6.1 MEDIUM
The reconcile method in the AttachmentReconciler class of the Halo system v.2.20.18LTS and before is vulnerable to XSS attacks.
CVE-2025-51053 1 Vedo Suite Project 1 Vedo Suite 2026-07-05 N/A 6.1 MEDIUM
A Cross-site scripting (XSS) vulnerability in /api_vedo/ in Vedo Suite version 2024.17 allows remote attackers to inject arbitrary Javascript or HTML code and potentially trigger code execution in victim's browser.
CVE-2025-50848 1 Cs-cart 1 Cs-cart 2026-07-05 N/A 6.1 MEDIUM
A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute arbitrary code. CS Cart 4.18.3 allows unrestricted upload of HTML files, which are rendered directly in the browser when accessed. This allows an attacker to upload a crafted HTML file containing malicious content, such as a fake login form for credential harvesting or scripts for Cross-Site Scripting (XSS) attacks. Since the content is served from a trusted domain, it significantly increases the likelihood of successful phishing or script execution against other users.
CVE-2025-50592 1 Seacms 1 Seacms 2026-07-05 N/A 5.4 MEDIUM
Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.
CVE-2025-50584 1 Daycloud 1 Studentmanage 2026-07-05 N/A 4.8 MEDIUM
StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Teacher module.
CVE-2025-50583 1 Daycloud 1 Studentmanage 2026-07-05 N/A 4.8 MEDIUM
StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module.
CVE-2025-50582 1 Daycloud 1 Studentmanage 2026-07-05 N/A 4.8 MEDIUM
StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Course module.
CVE-2025-50581 1 Mrcms 1 Mrcms 2026-07-05 N/A 4.8 MEDIUM
MRCMS v3.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/group/save.do.
CVE-2025-46102 1 Beakon 1 Learning Management System Sharable Content Object Reference Model 2026-07-05 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version V.5.4.3 allows a remote attacker to obtain sensitive information via the URL parameter
CVE-2025-46041 1 Anchorcms 1 Anchor Cms 2026-07-05 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the page creation interface (/admin/pages/add).
CVE-2025-45960 1 Tawk 1 Tawk.to 2026-07-05 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web application stores and displays user-supplied input without proper input validation or encoding
CVE-2025-45315 1 Hortusfox 1 Hortusfox 2026-07-05 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in the /controller/admin.php endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the email parameter.
CVE-2025-45314 1 Hortusfox 1 Hortusfox 2026-07-05 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the /Calendar endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the add function.
CVE-2025-45313 1 Hortusfox 1 Hortusfox 2026-07-05 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the /tasks endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the title parameter.
CVE-2025-45236 1 Dbsyncer Project 1 Dbsyncer 2026-07-05 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Nickname parameter.
CVE-2025-44148 1 Mailenable 1 Mailenable 2026-07-05 N/A 9.8 CRITICAL
Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component
CVE-2025-44141 1 Backdropcms 1 Backdrop Cms 2026-07-05 N/A 6.1 MEDIUM
A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30.