Vulnerabilities (CVE)

Filtered by CWE-79
Total 47297 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-45055 1 Silverpeas 1 Silverpeas 2026-06-17 N/A 5.4 MEDIUM
Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript in the admin's session. This allows attackers to escalate privileges by creating a new administrator account. The vulnerability arises from insufficient sanitization of SVG files and weak CSRF protections.
CVE-2025-45015 1 Phpgurukul 1 Park Ticketing Management System 2026-06-17 N/A 6.1 MEDIUM
A Cross-Site Scripting (XSS) vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. The vulnerability allows remote attackers to inject arbitrary JavaScript code via the fromdate and todate parameters.
CVE-2025-45007 1 Phpgurukul 1 Time Table Generator System 2026-06-17 N/A 4.8 MEDIUM
A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the profile.php file of PHPGurukul Timetable Generator System v1.0. This vulnerability allows remote attackers to execute arbitrary JavaScript code via the adminname POST request parameter.
CVE-2025-45002 1 Codervivek 1 Vigybag 2026-06-17 N/A 5.4 MEDIUM
Vigybag v1.0 and before is vulnerable to Cross Site Scripting (XSS) via the upload profile picture function under my profile.
CVE-2025-44998 1 Prasathmani 1 Tiny File Manager 2026-06-17 N/A 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.
CVE-2025-44595 1 Halo 1 Halo 2026-06-17 N/A 6.1 MEDIUM
Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}.
CVE-2025-44593 1 Halo 1 Halo 2026-06-17 N/A 6.1 MEDIUM
Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can trigger stored XSS vulnerabilities. This vulnerability is fixed in 2.20.13
CVE-2025-44206 2026-06-17 N/A 4.6 MEDIUM
Hexagon HxGN OnCall Dispatch Advantage (Web) v10.2309.03.00264 and Hexagon HxGN OnCall Dispatch Advantage (Mobile) v10.2402 are vulnerable to Cross Site Scripting (XSS) which allows a remote authenticated attacker with access to the Broadcast (Person) functionality to execute arbitrary code.
CVE-2025-44184 1 Mayurik 1 Best Employee Management System 2026-06-17 N/A 4.8 MEDIUM
SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the website_image, fname, lname, contact, username, and address parameters.
CVE-2025-44183 1 Anujk305 1 Vehicle Record Management System 2026-06-17 N/A 6.1 MEDIUM
Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the name, email, and mobile parameters.
CVE-2025-44182 1 Anujk305 1 Vehicle Record Management System 2026-06-17 N/A 6.1 MEDIUM
Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the vehiclename, modelnumber, regnumber, vehiclesubtype, chasisnum, enginenumber' in the /admin/edit-vehicle.php component. This allows attackers to execute arbitrary code.
CVE-2025-44181 1 Anujk305 1 Vehicle Record Management System 2026-06-17 N/A 6.1 MEDIUM
Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/add-brand.php via the brandname parameter.
CVE-2025-44180 1 Anujk305 1 Vehicle Record Management System 2026-06-17 N/A 6.1 MEDIUM
Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit-brand.php?bid={brandId}.
CVE-2025-44136 1 Maptiler 1 Tileserver Php 2026-06-17 N/A 9.8 CRITICAL
MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.
CVE-2025-44115 1 Cotonti 1 Cotonti Siena 2026-06-17 N/A 5.4 MEDIUM
A vulnerability has been found in Cotonti Siena v0.9.25. Affected by this vulnerability is the file /admin.php?m=config&n=edit&o=core&p=title. The manipulation of the value of title leads to cross-site scripting.
CVE-2025-44110 1 Fluxbb 1 Fluxbb 2026-06-17 N/A 5.4 MEDIUM
FluxBB 1.5.11 is vulnerable to Cross Site Scripting (XSS) in via the Forum Description Field in admin_forums.php.
CVE-2025-44108 1 Flatpress 1 Flatpress 2026-06-17 N/A 4.8 MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability exists in the administration panel of Flatpress CMS before 1.4 via the gallery captions component. An attacker with admin privileges can inject a malicious JavaScript payload into the system, which is then stored persistently.
CVE-2025-44091 1 Yangyouwang 1 Crud 2026-06-17 N/A 5.4 MEDIUM
yangyouwang crud v1.0.0 is vulnerable to Cross Site Scripting (XSS) via the role management function.
CVE-2025-44024 2026-06-17 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability was discovered in the Pichome system v2.1.0 and before. The vulnerability exists due to insufficient sanitization of user input in the login form. An attacker can inject malicious JavaScript code into the username or password fields during the login process
CVE-2025-44000 1 Meddream 1 Pacs Server 2026-06-17 N/A 6.1 MEDIUM
A reflected cross-site scripting (xss) vulnerability exists in the sendOruReport functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.