Vulnerabilities (CVE)

Filtered by CWE-79
Total 47282 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-57151 1 Phpgurukul 1 Complaint Management System 2026-06-17 N/A 8.8 HIGH
phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the fullname parameter.
CVE-2025-57150 1 Phpgurukul 1 Complaint Management System 2026-06-17 N/A 7.2 HIGH
phpgurukul Complaint Management System in PHP 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/subcategory.php via the categoryName parameter.
CVE-2025-56795 1 Mealie 1 Mealie 2026-06-17 N/A 9.0 CRITICAL
Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user input in the "note" and "text" fields of the "/api/recipes/{recipe_name}" endpoint is rendered in the frontend without proper escaping leading to persistent XSS.
CVE-2025-56762 1 Paracrawl 1 Keops 2026-06-17 N/A 6.1 MEDIUM
Paracrawl KeOPs v2 is vulnerable to Cross Site Scripting (XSS) in error.php.
CVE-2025-56761 1 Usememos 1 Memos 2026-06-17 N/A 5.4 MEDIUM
Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uploaded data and serve it back as is. An authenticated attacker can use this to elevate their privileges when the stored XSS is viewed by an admin.
CVE-2025-56697 1 Askar634 1 Computer Base Test 2026-06-17 N/A 6.1 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the /users/adminpanel/admin/home.php?page=feedbacks file of Kashipara Computer Base Test v1.0. Attackers can inject malicious scripts via the smyFeedbacks POST parameter in /users/home.php.
CVE-2025-56683 2026-06-17 N/A 9.6 CRITICAL
A cross-site scripting (XSS) vulnerability in the component /app/marketplace.html of Logseq v0.10.9 allows attackers to execute arbitrary code via injecting arbitrary Javascript into a crafted README.md file.
CVE-2025-56605 2026-06-17 N/A 5.4 MEDIUM
A reflected Cross-Site Scripting (XSS) vulnerability exists in the register.php backend script of PuneethReddyHC Event Management System 1.0. The mobile POST parameter is improperly validated and echoed back in the HTTP response without sanitization, allowing an attacker to inject and execute arbitrary JavaScript code in the victim's browser.
CVE-2025-56537 1 Opennebula 1 Opennebula 2026-06-17 N/A 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the virtual network template parameter.
CVE-2025-56536 1 Opennebula 1 Opennebula 2026-06-17 N/A 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the user information parameter.
CVE-2025-56535 1 Opennebula 1 Opennebula 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the zone attribute parameter.
CVE-2025-56534 1 Opennebula 1 Opennebula 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2025-56526 1 Cinnamon 1 Kotaemon 2026-06-17 N/A 6.1 MEDIUM
Cross site scripting (XSS) vulnerability in Kotaemon 0.11.0 allowing attackers to execute arbitrary code via a crafted PDF.
CVE-2025-56515 1 Suisuijiang 1 Fiora 2026-06-17 N/A 8.8 HIGH
File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fails to validate SVG file content, allowing malicious SVG files with embedded foreignObject elements containing iframe tags and JavaScript event handlers (onmouseover) to be uploaded and stored. When rendered, these SVG files execute arbitrary JavaScript, enabling attackers to steal user sessions, cookies, and perform unauthorized actions in the context of users viewing affected profiles.
CVE-2025-56514 1 Suisuijiang 1 Fiora 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows executes arbitrary JavaScript when malicious SVG files are rendered by other users.
CVE-2025-56451 1 Seeyon 1 A8\+ Collaborative Management 2026-06-17 N/A 6.1 MEDIUM
Cross site scripting vulnerability in seeyon Zhiyuan A8+ Collaborative Management Software 7.0 via the topValue parameter to the seeyon/main.do endpoint.
CVE-2025-56429 1 Fearlessgeekmedia 1 Fearlesscms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to obtain sensitive information via the login.php component.
CVE-2025-56382 1 Lion-coders 1 Salepro Pos 2026-06-17 N/A 6.1 MEDIUM
A stored Cross-site scripting (XSS) vulnerability exists in the Customer Management Module of LionCoders SalePro POS 5.4.8. An authenticated attacker can inject arbitrary web script or HTML via the 'Customer Name' parameter when creating or editing customer profiles. This malicious input is improperly sanitized before storage and subsequent rendering, leading to script execution in the browsers of users who view the affected customer details.
CVE-2025-56379 1 Frappe 2 Erpnext, Frappe 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the content field.
CVE-2025-56313 2026-06-17 N/A 6.1 MEDIUM
A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the /publix/run endpoint of JATOS 3.7.1 through 3.9.6 (inclusive). This allows remote attackers to execute arbitrary JavaScript in a user's web browser by including a malicious payload in the "code" URL parameter. When an authenticated admin user accesses the study's URL, the malicious script gets interpreted and executes within their browser, which can lead to unauthorized actions, account compromise, and privilege escalation.