Vulnerabilities (CVE)

Filtered by CWE-79
Total 47393 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-49211 1 Archerirm 1 Archer 2026-06-17 N/A 5.2 MEDIUM
Reflected XSS was discovered in a Dashboard Listing Archer Platform UX page in Archer Platform 6.x before version 2024.08. A remote unauthenticated attacker could potentially exploit this by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and executed by the web browser in the context of the vulnerable web application.
CVE-2024-49210 1 Archerirm 1 Archer 2026-06-17 N/A 5.2 MEDIUM
Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09. A remote unauthenticated attacker could potentially exploit this by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and executed by the web browser in the context of the vulnerable web application.
CVE-2024-49053 1 Microsoft 1 Dynamics 365 Sales 2026-06-17 N/A 7.6 HIGH
Microsoft Dynamics 365 Sales Spoofing Vulnerability
CVE-2024-49038 1 Microsoft 1 Copilot Studio 2026-06-17 N/A 9.3 CRITICAL
Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.
CVE-2024-48937 1 Znuny 1 Znuny 2026-06-17 N/A 6.1 MEDIUM
Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of the SLA field in Activity Dialogues is executed.
CVE-2024-48933 1 Lemonldap-ng 1 Lemonldap\ 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been set to a non-default value that allows special HTML characters.
CVE-2024-48927 1 Umbraco 1 Umbraco Cms 2026-06-17 N/A 4.6 MEDIUM
Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x prior to 8.18.15. There is a potential risk of code execution for Backoffice users when they “preview” SVG files in full screen mode. Versions 13.5.2, 10.8,7, and 8.18.15 contain a patch for the issue. As a workaround, derver-side file validation is available to strip script tags from file's content during the file upload process.
CVE-2024-48906 1 Sematell 1 Replyone 2026-06-17 N/A 6.1 MEDIUM
Sematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name.
CVE-2024-48893 1 Fortinet 1 Fortisoar 2026-06-17 N/A 6.8 MEDIUM
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook.
CVE-2024-48870 2 Sharp, Toshibatec 640 Bp-30c25, Bp-30c25 Firmware, Bp-30c25t and 637 more 2026-06-17 N/A 6.2 MEDIUM
Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users.
CVE-2024-48821 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php component.
CVE-2024-48807 1 Phpgurukul 1 Doctor Appointment Management System 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in PHPGurukul Doctor Appointment Management System v.1.0 allows a local attacker to execute arbitrary code via the search parameter.
CVE-2024-48761 1 Celk 1 Celk Saude 2026-06-17 N/A 8.8 HIGH
Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScript code via the "erro" parameter.
CVE-2024-48743 1 Telestream 1 Sentry 2026-06-17 N/A 6.5 MEDIUM
Cross Site Scripting vulnerability in Sentry v.6.0.9 allows a remote attacker to execute arbitrary code via the z parameter.
CVE-2024-48709 1 Codeastro 1 Membership Management System 2026-06-17 N/A 5.4 MEDIUM
CodeAstro Membership Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via the membershipType parameter in edit_type.php
CVE-2024-48708 1 O-dyn 1 Collabtive 2026-06-17 N/A 5.4 MEDIUM
Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php under action = adduser/edituser.
CVE-2024-48707 1 O-dyn 1 Collabtive 2026-06-17 N/A 5.4 MEDIUM
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within admin.php file.
CVE-2024-48706 1 O-dyn 1 Collabtive 2026-06-17 N/A 5.4 MEDIUM
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively.
CVE-2024-48704 1 Phpgurukul 1 Medical Card Generation System 2026-06-17 N/A 6.1 MEDIUM
Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter pagedes.
CVE-2024-48703 1 Anujk305 1 Medical Card Generation System 2026-06-17 N/A 4.8 MEDIUM
PhpGurukul Medical Card Generation System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/search-medicalcard.php via the searchdata parameter.