Total
47376 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-58291 | 2026-06-17 | N/A | N/A | ||
| Flatboard 3.2 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts in forum information fields. Attackers can insert JavaScript payloads that execute when other users view the forum, potentially stealing session cookies and executing client-side scripts. | |||||
| CVE-2024-58289 | 1 Microweber | 1 Microweber | 2026-06-17 | N/A | 5.4 MEDIUM |
| Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other users, potentially stealing session cookies and executing arbitrary JavaScript. | |||||
| CVE-2024-58285 | 1 Chyrp | 1 Chyrp | 2026-06-17 | N/A | 5.4 MEDIUM |
| Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into post titles. Attackers can craft payloads in the title field that will execute when the post is viewed by other users, potentially stealing session cookies or performing client-side attacks. | |||||
| CVE-2024-57783 | 2026-06-17 | N/A | 8.1 HIGH | ||
| The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs. | |||||
| CVE-2024-57776 | 1 Jfinaloa Project | 1 Jfinaloa | 2026-06-17 | N/A | 4.6 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2024-57774 | 1 Jfinaloa Project | 1 Jfinaloa | 2026-06-17 | N/A | 4.8 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2024-57773 | 1 Jfinaloa Project | 1 Jfinaloa | 2026-06-17 | N/A | 4.8 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2024-57772 | 1 Jfinaloa Project | 1 Jfinaloa | 2026-06-17 | N/A | 4.8 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2024-57771 | 1 Jfinaloa Project | 1 Jfinaloa | 2026-06-17 | N/A | 4.8 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |||||
| CVE-2024-57686 | 1 Phpgurukul | 1 Land Record System | 2026-06-17 | N/A | 9.8 CRITICAL |
| A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "pagetitle" parameter. | |||||
| CVE-2024-57605 | 1 Thedaylightstudio | 1 Fuel Cms | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the /fuel/blocks/ and /fuel/pages components. | |||||
| CVE-2024-57601 | 1 Easyappointments | 1 Easyappointments | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter. | |||||
| CVE-2024-57599 | 1 Douco | 1 Douphp | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in /admin/article.php | |||||
| CVE-2024-57556 | 1 Nbubna | 1 Store | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in nbubna store v.2.14.2 and before allows a remote attacker to execute arbitrary code via the store.deep.js component | |||||
| CVE-2024-57522 | 1 Oretnom23 | 1 Packers And Movers Management System | 2026-06-17 | N/A | 6.4 MEDIUM |
| SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject a malicious script into the username or name field during user creation. | |||||
| CVE-2024-57514 | 2026-06-17 | N/A | 4.8 MEDIUM | ||
| The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listing paths in the web interface. When a specially crafted URL is visited, the router's web page renders the directory listing and executes arbitrary JavaScript embedded in the URL. This allows the attacker to inject malicious code into the page, executing JavaScript on the victim's browser, which could then be used for further malicious actions. The vulnerability was identified in the 1.0.6 Build 20231011 rel.85717(5553) version. | |||||
| CVE-2024-57498 | 1 Forestblog Project | 1 Forestblog | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the article editing function. | |||||
| CVE-2024-57494 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalate privileges via the kw parameter. | |||||
| CVE-2024-57488 | 1 Code-projects | 1 Online Car Rental System | 2026-06-17 | N/A | 6.5 MEDIUM |
| Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter in /admin/edit-vehicle.php. | |||||
| CVE-2024-57428 | 1 Phpjabbers | 1 Cinema Booking System | 2026-06-17 | N/A | 9.3 CRITICAL |
| A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, malware injection, and session hijacking. | |||||
