Total
47246 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-52206 | 1 Ispconfig | 1 Ispconfig | 2026-07-05 | N/A | 4.7 MEDIUM |
| ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage. | |||||
| CVE-2025-51965 | 2026-07-05 | N/A | 6.1 MEDIUM | ||
| OURPHP thru 8.6.1 is vulnerable to Cross-Site Scripting (XSS) via the "Name" field of the "Complete Profile" functionality under the "My User Center" page, which can be accessed after registering through the front-end interface. | |||||
| CVE-2025-52169 | 2026-07-05 | N/A | 7.1 HIGH | ||
| agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability. | |||||
| CVE-2025-51857 | 2026-07-05 | N/A | 6.1 MEDIUM | ||
| The reconcile method in the AttachmentReconciler class of the Halo system v.2.20.18LTS and before is vulnerable to XSS attacks. | |||||
| CVE-2025-51053 | 1 Vedo Suite Project | 1 Vedo Suite | 2026-07-05 | N/A | 6.1 MEDIUM |
| A Cross-site scripting (XSS) vulnerability in /api_vedo/ in Vedo Suite version 2024.17 allows remote attackers to inject arbitrary Javascript or HTML code and potentially trigger code execution in victim's browser. | |||||
| CVE-2025-50848 | 1 Cs-cart | 1 Cs-cart | 2026-07-05 | N/A | 6.1 MEDIUM |
| A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute arbitrary code. CS Cart 4.18.3 allows unrestricted upload of HTML files, which are rendered directly in the browser when accessed. This allows an attacker to upload a crafted HTML file containing malicious content, such as a fake login form for credential harvesting or scripts for Cross-Site Scripting (XSS) attacks. Since the content is served from a trusted domain, it significantly increases the likelihood of successful phishing or script execution against other users. | |||||
| CVE-2025-50592 | 1 Seacms | 1 Seacms | 2026-07-05 | N/A | 5.4 MEDIUM |
| Cross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player. | |||||
| CVE-2025-50584 | 1 Daycloud | 1 Studentmanage | 2026-07-05 | N/A | 4.8 MEDIUM |
| StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Teacher module. | |||||
| CVE-2025-50583 | 1 Daycloud | 1 Studentmanage | 2026-07-05 | N/A | 4.8 MEDIUM |
| StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module. | |||||
| CVE-2025-50582 | 1 Daycloud | 1 Studentmanage | 2026-07-05 | N/A | 4.8 MEDIUM |
| StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Course module. | |||||
| CVE-2025-50581 | 1 Mrcms | 1 Mrcms | 2026-07-05 | N/A | 4.8 MEDIUM |
| MRCMS v3.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/group/save.do. | |||||
| CVE-2025-46102 | 1 Beakon | 1 Learning Management System Sharable Content Object Reference Model | 2026-07-05 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version V.5.4.3 allows a remote attacker to obtain sensitive information via the URL parameter | |||||
| CVE-2025-46041 | 1 Anchorcms | 1 Anchor Cms | 2026-07-05 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the page creation interface (/admin/pages/add). | |||||
| CVE-2025-45960 | 1 Tawk | 1 Tawk.to | 2026-07-05 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web application stores and displays user-supplied input without proper input validation or encoding | |||||
| CVE-2025-45315 | 1 Hortusfox | 1 Hortusfox | 2026-07-05 | N/A | 5.4 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the /controller/admin.php endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the email parameter. | |||||
| CVE-2025-45314 | 1 Hortusfox | 1 Hortusfox | 2026-07-05 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the /Calendar endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the add function. | |||||
| CVE-2025-45313 | 1 Hortusfox | 1 Hortusfox | 2026-07-05 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the /tasks endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the title parameter. | |||||
| CVE-2025-45236 | 1 Dbsyncer Project | 1 Dbsyncer | 2026-07-05 | N/A | 5.4 MEDIUM |
| A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Nickname parameter. | |||||
| CVE-2025-44148 | 1 Mailenable | 1 Mailenable | 2026-07-05 | N/A | 9.8 CRITICAL |
| Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx component | |||||
| CVE-2025-44141 | 1 Backdropcms | 1 Backdrop Cms | 2026-07-05 | N/A | 6.1 MEDIUM |
| A Cross-Site Scripting (XSS) vulnerability exists in the node creation form of Backdrop CMS 1.30. | |||||
