Vulnerabilities (CVE)

Filtered by CWE-79
Total 47395 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-46209 1 Redaxo 1 Redaxo 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the password parameter.
CVE-2024-46083 1 Scriptcase 1 Scriptcase 2026-06-17 N/A 5.4 MEDIUM
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads using the messages feature, which allows the injection of malicious code into any user's account on the platform. It is important to note that regular users can trigger actions for administrator users.
CVE-2024-46082 1 Scriptcase 1 Scriptcase 2026-06-17 N/A 5.4 MEDIUM
Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parameters.
CVE-2024-46081 1 Scriptcase 1 Scriptcase 2026-06-17 N/A 5.4 MEDIUM
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious payloads in the To-Do List. The assigned user will trigger a stored XSS, which is particularly dangerous because tasks are assigned to various users on the platform.
CVE-2024-46079 1 Scriptcase 1 Scriptcase 2026-06-17 N/A 6.1 MEDIUM
Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.
CVE-2024-46077 1 Mayurik 1 Online Tours And Travels Management System 2026-06-17 N/A 5.4 MEDIUM
itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.
CVE-2024-46073 2026-06-17 N/A 6.1 MEDIUM
A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the "next" parameter, which is included in the application's response without adequate escaping. An attacker can exploit this flaw by tricking a user into visiting a specially crafted URL, causing the execution of arbitrary JavaScript code in the context of the victim's browser. The issue occurs even though the application has sanitization mechanisms in place.
CVE-2024-46055 1 Davidguva 1 Openvidreview 2026-06-17 N/A 4.8 MEDIUM
OpenVidReview 1.0 is vulnerable to Cross Site Scripting (XSS) in review names.
CVE-2024-45986 1 Projectworlds 1 Online Voting System Project 2026-06-17 N/A 5.4 MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript payload. The payload is stored and subsequently executed in the voter.php and profile.php pages whenever the account information is accessed.
CVE-2024-45985 1 Varunsardana004 1 Blood Bank And Donation Management System 2026-06-17 N/A 4.7 MEDIUM
A Cross Site Scripting (XSS) vulnerability in update_contact.php of Blood Bank and Donation Management System v1.0 allows an attacker to inject malicious scripts via the name parameter of the update_contact.php
CVE-2024-45984 1 Varunsardana004 1 Blood Bank And Donation Management System 2026-06-17 N/A 4.7 MEDIUM
A Cross Site Scripting (XSS) vulnerability in add_donor.php of Blood Bank And Donation Management System 1.0 allows an attacker to inject malicious scripts that will be executed when the Donor List is viewed.
CVE-2024-45967 1 Pagekit 1 Pagekit 2026-06-17 N/A 4.7 MEDIUM
Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.
CVE-2024-45964 1 Tribalsystems 1 Zenario 2026-06-17 N/A 4.8 MEDIUM
Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field.
CVE-2024-45962 1 Octobercms 1 October 2026-06-17 N/A 4.7 MEDIUM
October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted JavaScript to the target.
CVE-2024-45960 1 Tribalsystems 1 Zenario 2026-06-17 N/A 4.8 MEDIUM
Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the website, it can trigger a Cross Site Scripting (XSS) attack.
CVE-2024-45920 1 Solvait 1 Solvait 2026-06-17 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability in Solvait 24.4.2 allows remote attackers to inject malicious scripts into the application. This issue arises due to insufficient input validation and sanitization in "Intrest" feature.
CVE-2024-45879 2026-06-17 N/A 5.4 MEDIUM
The file upload function in the "QWKalkulation" tool of baltic-it TOPqw Webportal v1.35.287.1 (fixed in version 1.35.291), in /Apps/TOPqw/QWKalkulation/QWKalkulation.aspx, is vulnerable to Cross-Site Scripting (XSS). To exploit the persistent XSS vulnerability, an attacker has to be authenticated to the application that uses the "TOPqw Webportal" as a software. When authenticated, the attacker can persistently place the malicious JavaScript code in the "QWKalkulation" menu.'
CVE-2024-45878 2026-06-17 N/A 5.4 MEDIUM
The "Stammdaten" menu of baltic-it TOPqw Webportal v1.35.283.2 (fixed in version 1.35.291), in /Apps/TOPqw/qwStammdaten.aspx, is vulnerable to persistent Cross-Site Scripting (XSS).
CVE-2024-45856 1 Mindsdb 1 Mindsdb 2026-06-17 N/A 9.0 CRITICAL
A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI.
CVE-2024-45836 1 Planex 10 Cs-qr10, Cs-qr10 Firmware, Cs-qr20 and 7 more 2026-06-17 N/A 6.1 MEDIUM
Cross-site scripting vulnerability exists in the web management page of PLANEX COMMUNICATIONS network cameras. If a logged-in user accesses a specific file, an arbitrary script may be executed on the web browser of the user.