Total
47282 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-56280 | 1 Carmelo | 1 Food Ordering Review System | 2026-06-17 | N/A | 5.4 MEDIUM |
| code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the area where users submit reservation information. | |||||
| CVE-2025-56276 | 1 Carmelo | 1 Food Ordering Review System | 2026-06-17 | N/A | 5.4 MEDIUM |
| code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the registration function. An attacker enters malicious JavaScript code as a username, which triggers the XSS vulnerability when the admin views user information, resulting in the disclosure of the admin's cookie information. | |||||
| CVE-2025-56252 | 1 Pathinfotech | 1 Servitiumcrm | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (xss) vulnerability in ServitiumCRM 2.10 allowing attackers to execute arbitrary code via a crafted URL to the mobile parameter. | |||||
| CVE-2025-56243 | 1 Puneethreddyhc | 1 Event Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Cross-Site Scripting (XSS) vulnerability was found in the register.php page of PuneethReddyHC Event Management System 1.0, where the event_id GET parameter is improperly handled. An attacker can craft a malicious URL to execute arbitrary JavaScript in the victim s browser by injecting code into this parameter. | |||||
| CVE-2025-56236 | 1 Formcms | 1 Formcms | 2026-06-17 | N/A | 6.1 MEDIUM |
| FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated users can upload .html files containing malicious JavaScript, which are accessible via a public URL. When a privileged user accesses the file, the script executes in their browser context. | |||||
| CVE-2025-56154 | 1 Htmly | 1 Htmly | 2026-06-17 | N/A | 6.1 MEDIUM |
| htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflected in the HTML response, allowing attackers to inject arbitrary JavaScript payloads. | |||||
| CVE-2025-56018 | 1 Senior-walter | 1 Web-based Pharmacy Product Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| SourceCodester Web-based Pharmacy Product Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in Category Management via the category name field. | |||||
| CVE-2025-56008 | 1 Keenetic | 1 Keeneticos | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near to the router to takeover the device via adding additional users with full permissions. | |||||
| CVE-2025-55998 | 1 Mezereon | 1 Smart Search And Filter | 2026-06-17 | N/A | 8.1 HIGH |
| A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into several filter parameter | |||||
| CVE-2025-55996 | 1 Rakuten | 1 Viber | 2026-06-17 | N/A | 6.3 MEDIUM |
| Viber Desktop 25.6.0 is vulnerable to HTML Injection via the text parameter of the message compose/forward interface | |||||
| CVE-2025-55944 | 1 Slinkapp | 1 Slink | 2026-06-17 | N/A | 6.1 MEDIUM |
| Slink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views the shared image in a new browser tab, the embedded JavaScript executes. The issue affects both authenticated and unauthenticated users. | |||||
| CVE-2025-55834 | 1 Huayi-tec | 1 Jeewms | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Cross Site Scripting vulnerability in JeeWMS v.3.7 and before allows a remote attacker to obtain sensitive information via the logController.do component | |||||
| CVE-2025-55816 | 1 Digitaldruid | 1 Hoteldruid | 2026-06-17 | N/A | 6.1 MEDIUM |
| HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file. | |||||
| CVE-2025-55757 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered. | |||||
| CVE-2025-55742 | 1 Webkul | 1 Unopim | 2026-06-17 | N/A | 8.0 HIGH |
| UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, UnoPim contains a stored cross-site scripting vulnerability via SVG MIME/sanitizer bypass in the /admin/settings/users/create endpoint. This vulnerability is fixed in 0.2.1. | |||||
| CVE-2025-55735 | 1 Dogukanurker | 1 Flaskblog | 2026-06-17 | N/A | 5.4 MEDIUM |
| flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the content of the post stored in the variable "postContent". The vulnerability arises when displaying the content of the post using the | safe filter, that tells the engine to not escape the rendered content. This can lead to a stored XSS inside the content of the post. The code that causes the problem is in template/routes.html. | |||||
| CVE-2025-55714 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.9. | |||||
| CVE-2025-55713 | 2026-06-17 | N/A | 5.9 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativethemeshq Blocksy blocksy allows Stored XSS.This issue affects Blocksy: from n/a through <= 2.1.6. | |||||
| CVE-2025-55711 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Table Builder WP Table Builder wp-table-builder allows Stored XSS.This issue affects WP Table Builder: from n/a through <= 2.0.12. | |||||
| CVE-2025-55709 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer allows Stored XSS.This issue affects Visual Composer Website Builder: from n/a through < 45.15.0. | |||||
