Vulnerabilities (CVE)

Filtered by CWE-79
Total 47376 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-58291 2026-06-17 N/A N/A
Flatboard 3.2 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts in forum information fields. Attackers can insert JavaScript payloads that execute when other users view the forum, potentially stealing session cookies and executing client-side scripts.
CVE-2024-58289 1 Microweber 1 Microweber 2026-06-17 N/A 5.4 MEDIUM
Microweber 2.0.15 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into user profile fields. Attackers can input script payloads in the first name field that will execute when the profile is viewed by other users, potentially stealing session cookies and executing arbitrary JavaScript.
CVE-2024-58285 1 Chyrp 1 Chyrp 2026-06-17 N/A 5.4 MEDIUM
Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into post titles. Attackers can craft payloads in the title field that will execute when the post is viewed by other users, potentially stealing session cookies or performing client-side attacks.
CVE-2024-57783 2026-06-17 N/A 8.1 HIGH
The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.
CVE-2024-57776 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 4.6 MEDIUM
A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-57774 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-57773 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-57772 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-57771 1 Jfinaloa Project 1 Jfinaloa 2026-06-17 N/A 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-57686 1 Phpgurukul 1 Land Record System 2026-06-17 N/A 9.8 CRITICAL
A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "pagetitle" parameter.
CVE-2024-57605 1 Thedaylightstudio 1 Fuel Cms 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the /fuel/blocks/ and /fuel/pages components.
CVE-2024-57601 1 Easyappointments 1 Easyappointments 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter.
CVE-2024-57599 1 Douco 1 Douphp 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in /admin/article.php
CVE-2024-57556 1 Nbubna 1 Store 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in nbubna store v.2.14.2 and before allows a remote attacker to execute arbitrary code via the store.deep.js component
CVE-2024-57522 1 Oretnom23 1 Packers And Movers Management System 2026-06-17 N/A 6.4 MEDIUM
SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject a malicious script into the username or name field during user creation.
CVE-2024-57514 2026-06-17 N/A 4.8 MEDIUM
The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listing paths in the web interface. When a specially crafted URL is visited, the router's web page renders the directory listing and executes arbitrary JavaScript embedded in the URL. This allows the attacker to inject malicious code into the page, executing JavaScript on the victim's browser, which could then be used for further malicious actions. The vulnerability was identified in the 1.0.6 Build 20231011 rel.85717(5553) version.
CVE-2024-57498 1 Forestblog Project 1 Forestblog 2026-06-17 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the article editing function.
CVE-2024-57494 2026-06-17 N/A 6.5 MEDIUM
Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalate privileges via the kw parameter.
CVE-2024-57488 1 Code-projects 1 Online Car Rental System 2026-06-17 N/A 6.5 MEDIUM
Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter in /admin/edit-vehicle.php.
CVE-2024-57428 1 Phpjabbers 1 Cinema Booking System 2026-06-17 N/A 9.3 CRITICAL
A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number configurations (number[new_X] in pjActionCreate). Attackers can inject persistent JavaScript, leading to phishing, malware injection, and session hijacking.