Vulnerabilities (CVE)

Filtered by CWE-79
Total 47379 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-55492 1 Magicwinmail 1 Winmail Server 2026-06-17 N/A 6.1 MEDIUM
Winmail Server 4.4 is vulnerable to f_user=%22%3E%3Csvg%20onload Cross Site Scripting (XSS).
CVE-2024-55451 1 Ujcms 1 Ujcms 2026-06-17 N/A 4.8 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3. The vulnerability arises from insufficient sanitization of embedded attributes in uploaded SVG files. When a maliciously crafted SVG file is viewed by other backend users, it allows authenticated attackers to execute arbitrary JavaScript in the context of other backend users' browsers, potentially leading to the theft of sensitive tokens.
CVE-2024-55416 1 Thecontrolgroup 1 Voyager 2026-06-17 N/A 3.5 LOW
DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.
CVE-2024-55342 1 Dotnetfoundation 1 Piranha Cms 2026-06-17 N/A 4.7 MEDIUM
A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /manager/media. This PDF can contain malicious JavaScript code, which is executed when a victim user opens or interacts with the PDF in their web browser, leading to a XSS vulnerability.
CVE-2024-55341 1 Dotnetfoundation 1 Piranha Cms 2026-06-17 N/A 4.7 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by creating a page via the /manager/pages and then adding a markdown content with the XSS payload.
CVE-2024-55279 1 Uguu 1 Uguu 2026-06-17 N/A 6.0 MEDIUM
Uguu through 1.8.9 allows Cross Site Scripting (XSS) via JavaScript in XML files.
CVE-2024-55268 1 Phpgurukul 1 Covid 19 Testing Management System 2026-06-17 N/A 6.1 MEDIUM
A Reflected Cross Site Scripting (XSS) vulnerability was found in /covidtms/registered-user-testing.php in PHPGurukul COVID 19 Testing Management System 1.0 which allows remote attackers to execute arbitrary code via the regmobilenumber parameter.
CVE-2024-55239 1 Portabilis 1 I-educar 2026-06-17 N/A 5.4 MEDIUM
A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows attacker to craft malicious urls with arbitrary javascript in the 'titulo_documento' parameter.
CVE-2024-55228 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 N/A 9.0 CRITICAL
A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.
CVE-2024-55227 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 N/A 9.0 CRITICAL
A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.
CVE-2024-55226 1 Dani-garcia 1 Vaultwarden 2026-06-17 N/A 5.4 MEDIUM
Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs.
CVE-2024-55224 1 Dani-garcia 1 Vaultwarden 2026-06-17 N/A 9.6 CRITICAL
An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.
CVE-2024-55218 1 Icewarp 1 Icewarp 2026-06-17 N/A 6.1 MEDIUM
IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.
CVE-2024-55199 1 Celk 1 Celk Saude 2026-06-17 N/A 5.4 MEDIUM
A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file upload feature. When the file is rendered, the injected code is executed on the user's browser.
CVE-2024-55100 1 Phpgurukul 1 Online Nurse Hiring System 2026-06-17 N/A 4.8 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Online Nurse Hiring System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fullname parameter.
CVE-2024-55093 1 Phpipam 1 Phpipam 2026-06-17 N/A 5.4 MEDIUM
phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts.
CVE-2024-55074 1 Grocy Project 1 Grocy 2026-06-17 N/A 8.8 HIGH
The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370.
CVE-2024-55064 1 Easyvirt 1 Dc Netscope 2026-06-17 N/A 5.4 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in EasyVirt DC NetScope <= 8.6.4 allow remote attackers to inject arbitrary JavaScript or HTML code via the (1) smtp_server, (2) smtp_account, (3) smtp_password, or (4) email_recipients parameter to /smtp/update; the (5) ntp or (6) dns parameter to /proxy/ntp/change; the (7) newVcenterAddress parameter to /process_new_vcenter.
CVE-2024-55060 1 Rafed-system 1 Rafed Cms Website 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-55059 1 Phpgurukul 1 Online Birth Certificate System 2026-06-17 N/A 6.1 MEDIUM
A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certificate-form.php.