Total
47317 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-26541 | 2026-06-17 | N/A | 7.1 HIGH | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce woo-altcoin-payment-gateway allows Reflected XSS.This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: from n/a through <= 1.7.6. | |||||
| CVE-2025-26539 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in petkivim Embed Google Map embed-google-map allows Stored XSS.This issue affects Embed Google Map: from n/a through <= 3.2. | |||||
| CVE-2025-26538 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Prezi Embedder prezi-embedder allows Stored XSS.This issue affects Prezi Embedder: from n/a through <= 2.1. | |||||
| CVE-2025-26537 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rolomak GDPR Tools gdpr-tools allows Stored XSS.This issue affects GDPR Tools: from n/a through <= 1.0.2. | |||||
| CVE-2025-26536 | 2026-06-17 | N/A | 7.1 HIGH | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yendif Player Another Events Calendar another-events-calendar allows Reflected XSS.This issue affects Another Events Calendar: from n/a through <= 1.7.0. | |||||
| CVE-2025-26530 | 1 Moodle | 1 Moodle | 2026-06-17 | N/A | 8.3 HIGH |
| The question bank filter required additional sanitizing to prevent a reflected XSS risk. | |||||
| CVE-2025-26529 | 1 Moodle | 1 Moodle | 2026-06-17 | N/A | 8.3 HIGH |
| Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk. | |||||
| CVE-2025-26528 | 1 Moodle | 1 Moodle | 2026-06-17 | N/A | 3.4 LOW |
| The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk. | |||||
| CVE-2025-26514 | 1 Netapp | 1 Storagegrid | 2026-06-17 | N/A | 6.4 MEDIUM |
| StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cross-Site Scripting vulnerability. Successful exploit could allow an attacker to view or modify configuration settings or add or modify user accounts but requires the attacker to know specific information about the target instance and then trick a privileged user into clicking a specially crafted link. | |||||
| CVE-2025-26493 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.6 MEDIUM |
| In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab | |||||
| CVE-2025-26395 | 1 Solarwinds | 1 Observability Self-hosted | 2026-06-17 | N/A | 7.1 HIGH |
| SolarWinds Observability Self-Hosted was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitized field in the URL. The attack requires authentication using an administrator-level account and user interaction is required. | |||||
| CVE-2025-26391 | 1 Solarwinds | 1 Observability Self-hosted | 2026-06-17 | N/A | 5.4 MEDIUM |
| SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account. | |||||
| CVE-2025-26258 | 1 Remyandrade | 1 Employee Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| Sourcecodester Employee Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via 'Add Designation.' | |||||
| CVE-2025-26210 | 1 Deepseek | 3 Deepseek-r1, Deepseek-v2, Deepseek-v3 | 2026-06-17 | N/A | 8.8 HIGH |
| DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain. NOTE: some third parties have indicated that this is intended behavior. | |||||
| CVE-2025-26202 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Cross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4GHz & 5GHz bands) in DZS Router Web Interface. An authenticated attacker can inject malicious JavaScript into the passphrase field, which is stored and later executed when an administrator views the passphrase via the "Click here to display" option on the Status page | |||||
| CVE-2025-26159 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can inject malicious JavaScript code in the name field. | |||||
| CVE-2025-26158 | 1 Kashipara | 1 Online Attendance Management System | 2026-06-17 | N/A | 5.6 MEDIUM |
| A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the department parameter. | |||||
| CVE-2025-26153 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, such as administrators, reply to the message. | |||||
| CVE-2025-26127 | 2026-06-17 | N/A | 5.0 MEDIUM | ||
| A stored cross-site scripting (XSS) vulnerability in the Send for Approval function of FileCloud v23.241.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2025-26091 | 1 Teampasswordmanager | 1 Team Password Manager | 2026-06-17 | N/A | 4.6 MEDIUM |
| A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new password in the "My Passwords" page. | |||||
