Vulnerabilities (CVE)

Filtered by CWE-79
Total 47376 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-57427 1 Phpjabbers 1 Cinema Booking System 2026-06-17 N/A 6.1 MEDIUM
PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s browser. Attackers can craft malicious links to steal session cookies or conduct phishing attacks.
CVE-2024-57423 1 Vishalmathur 1 Cloudclassroom-php Project 2026-06-17 N/A 6.1 MEDIUM
A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function.
CVE-2024-57409 1 Beian.miit 1 Cool-admin-java 2026-06-17 N/A 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the internet pictures field.
CVE-2024-57386 1 Wallosapp 1 Wallos 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function.
CVE-2024-57372 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters
CVE-2024-57348 1 Pecanproject 1 Pecan 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in PecanProject pecan through v.1.8.0 allows a remote attacker to execute arbitrary code via the crafted payload to the hostname, sitegroupid, lat, lon and sitename parameters.
CVE-2024-57329 1 Hortusfox 1 Hortusfox 2026-06-17 N/A 5.4 MEDIUM
HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.
CVE-2024-57326 1 Online Pizza Delivery System Project 1 Online Pizza Delivery System 2026-06-17 N/A 6.1 MEDIUM
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the search.php file of the Online Pizza Delivery System 1.0. The vulnerability allows an attacker to execute arbitrary JavaScript code in the browser via unsanitized input passed through the search parameter.
CVE-2024-57279 2026-06-17 N/A 5.4 MEDIUM
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in the LDAP User Manager <= ce92321, specifically in the /setup/index.php endpoint via the returnto parameter. This vulnerability arises due to improper sanitization of user-supplied input, allowing an attacker to inject malicious JavaScript.
CVE-2024-57278 2026-06-17 N/A 5.4 MEDIUM
A reflected Cross-Site Scripting (XSS) vulnerability exists in /webscan/sqlmap/index.html in QingScan <=v1.8.0. The vulnerability is caused by improper input sanitization of the query parameter, allowing an attacker to inject malicious JavaScript payloads. When a victim accesses a crafted URL containing the malicious input, the script executes in the victim's browser context.
CVE-2024-57277 2026-06-17 N/A 5.7 MEDIUM
InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
CVE-2024-57272 2026-06-17 N/A 6.1 MEDIUM
SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower is vulnerable to Cross Site Scripting (XSS).
CVE-2024-57240 1 Apryse 1 Webviewer 2026-06-17 N/A 5.4 MEDIUM
A Cross-Site Scripting (XSS) vulnerability in the Rendering Engine component in Apryse WebViewer v11.1 and earlier allows attackers to execute arbitrary code via a crafted PDF file.
CVE-2024-57237 2026-06-17 N/A 6.3 MEDIUM
Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endpoint. The vulnerability arises because the cmd parameter does not properly sanitize input and the response is served with a Content-Type of text/html. This behavior allows the browser to execute injected JavaScript code.
CVE-2024-57175 1 Phpgurukul 1 Online Birth Certificate System 2026-06-17 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 via the profile name to /user/certificate-form.php.
CVE-2024-57097 1 Classcms 1 Classcms 2026-06-17 N/A 4.8 MEDIUM
ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php.
CVE-2024-57033 1 Wegia 1 Wegia 2026-06-17 N/A 6.1 MEDIUM
WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php.
CVE-2024-57030 1 Wegia 1 Wegia 2026-06-17 N/A 8.1 HIGH
Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.
CVE-2024-57026 1 Tawk 1 Tawk.to 2026-06-17 N/A 6.1 MEDIUM
TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that allows JavaScript execution.
CVE-2024-56998 1 Phpgurukul 1 Hospital Management System 2026-06-17 N/A 4.2 MEDIUM
PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /edit-profile.php via the parameter $address.