Vulnerabilities (CVE)

Filtered by CWE-79
Total 47317 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-26065 1 Intelbras 4 Rx 1500, Rx 1500 Firmware, Rx 3000 and 1 more 2026-06-17 N/A 7.3 HIGH
A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name of a visiting Wi-Fi network.
CVE-2025-26064 1 Intelbras 4 Rx 1500, Rx 1500 Firmware, Rx 3000 and 1 more 2026-06-17 N/A 7.3 HIGH
A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name of a connnected device.
CVE-2025-26054 2026-06-17 N/A 5.4 MEDIUM
Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the "Description" field during LAN configuration.
CVE-2025-25990 1 Hoosk 1 Hoosk 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in hooskcms v.1.7.1 allows a remote attacker to obtain sensitive information via the /install/index.php component.
CVE-2025-25988 1 Hoosk 1 Hoosk 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability in hooskcms v.1.8 allows a remote attacker to cause a denial of service via the custom Link title parameter and the Title parameter.
CVE-2025-25973 1 Yandaozi 1 Ppress 2026-06-17 N/A 6.5 MEDIUM
A stored Cross Site Scripting vulnerability in the "related recommendations" feature in Ppress v.0.0.9 allows a remote attacker to execute arbitrary code via a crafted script to the article.title, article.category, and article.tags parameters.
CVE-2025-25960 1 Phpcms 1 Phpcms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via the menu interface of the member center of the background administrator.
CVE-2025-25958 1 Phpcms 1 Phpcms 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 allows a remote attacker to escalate privileges via a crafted script.
CVE-2025-25957 1 Xunruicms 1 Xunruicms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerabilities in Xunruicms v.4.6.3 and before allows a remote attacker to escalate privileges via a crafted script.
CVE-2025-25949 1 Academiaerp 1 Student Information System 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the User ID parameter at /rest/staffResource/update.
CVE-2025-25939 1 Reprisesoftware 1 Reprise License Manager 2026-06-17 N/A 6.1 MEDIUM
Reprise License Manager 14.2 is vulnerable to reflected cross-site scripting in /goform/activate_process via the akey parameter.
CVE-2025-25929 1 Openmrs 1 Openmrs 2026-06-17 N/A 5.4 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in the component /legacyui/quickReportServlet of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the reportType parameter.
CVE-2025-25916 1 Wuzhicms 1 Wuzhicms 2026-06-17 N/A 5.4 MEDIUM
wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php.
CVE-2025-25908 1 Tianti Project 1 Tianti 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the coverImageURL parameter at /article/ajax/save.
CVE-2025-25905 1 4pace 1 Cadclick 2026-06-17 N/A 7.1 HIGH
Cross-Site Scripting (XSS) vulnerability in CADClick v1.13.0 and before allows remote attackers to inject arbitrary web script or HTML via the "tree" parameter.
CVE-2025-25776 1 Codeastro 1 Bus Ticket Booking System 2026-06-17 N/A 5.0 MEDIUM
Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing.
CVE-2025-25747 1 Digitaldruid 1 Hoteldruid 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint
CVE-2025-25625 1 Fs 2 S3150-8t2f, S3150-8t2f Firmware 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting vulnerability exists in FS model S3150-8T2F switches running firmware s3150-8t2f-switch-fsos-220d_118101 and web firmware v2.2.2, which allows an authenticated web interface user to bypass input filtering on user names, and stores un-sanitized HTML and Javascript on the device. Pages which then present the user name without encoding special characters will then cause the injected code to be parsed by the browsers of other users accessing the web interface.
CVE-2025-25620 1 Changeweb 1 Unifiedtransform 2026-06-17 N/A 5.4 MEDIUM
Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function.
CVE-2025-25476 1 Syspass 1 Syspass 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious XSS payload as a notification type or notification component.