Vulnerabilities (CVE)

Filtered by CWE-79
Total 47419 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-39307 2026-06-17 N/A 3.5 LOW
Kavita is a cross platform reading server. Opening an ebook with malicious scripts inside leads to code execution inside the browsing context. Kavita doesn't sanitize or sandbox the contents of epubs, allowing scripts inside ebooks to execute. This vulnerability was patched in version 0.8.1.
CVE-2024-39272 1 Clear 1 Clearml Enterprise Server 2026-06-17 N/A 9.0 CRITICAL
A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to an arbitrary html code. An attacker can send a series of HTTP requests to trigger this vulnerability.
CVE-2024-39248 1 Fikeulous 1 Simpcms 2026-06-17 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in SimpCMS v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field at /admin.php.
CVE-2024-39242 1 Skycaiji 1 Skycaiji 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in skycaiji v2.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload using eval(String.fromCharCode()).
CVE-2024-39241 1 Skycaiji 1 Skycaiji 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in skycaiji 2.8 allows attackers to run arbitrary code via /admin/tool/preview.
CVE-2024-39203 1 Zblogcn 1 Z-blogphp 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the Backend Theme Management module of Z-BlogPHP v1.7.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-39174 1 Yzmcms 1 Yzmcms 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a published article.
CVE-2024-39162 2026-06-17 N/A 6.1 MEDIUM
pyspider through 0.3.10 allows /update XSS. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2024-39143 1 Coderberg 1 Residencecms 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to create malicious property content with HTML inside which acts as a stored XSS payload.
CVE-2024-39126 1 Roundup-tracker 1 Roundup 2026-06-17 N/A 5.4 MEDIUM
Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.
CVE-2024-39125 1 Roundup-tracker 1 Roundup 2026-06-17 N/A 5.4 MEDIUM
Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.
CVE-2024-39124 1 Roundup-tracker 1 Roundup 2026-06-17 N/A 5.4 MEDIUM
In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS.
CVE-2024-39123 1 Janeczku 1 Calibre-web 2026-06-17 N/A 5.4 MEDIUM
In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization.
CVE-2024-39094 1 Friendica 1 Friendica 2026-06-17 N/A 5.4 MEDIUM
Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix parameters.
CVE-2024-39031 1 Silverpeas 1 Silverpeas 2026-06-17 N/A 5.4 MEDIUM
In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite others from the same domain, including administrators, to these events. A standard user can inject an XSS payload into the "Titre" and "Description" fields when creating an event and then add the administrator or any user to the event. When the invited user (victim) views their own profile, the payload will be executed on their side, even if they do not click on the event.
CVE-2024-38972 1 Netbox 1 Netbox 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-ports/add/.
CVE-2024-38971 1 Vaethink 1 Vaethink 2026-06-17 N/A 5.4 MEDIUM
vaeThink 1.0.2 is vulnerable to stored Cross Site Scripting (XSS) in the system backend.
CVE-2024-38963 1 Nopcommerce 1 Nopcommerce 2026-06-17 N/A 6.1 MEDIUM
Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProductReview.ReviewText" parameter(s) (Reviews) when creating a new review.
CVE-2024-38959 1 Creativeitem 1 Academy Lms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Creativeitem Academy LMS Learning Management System v.6.8.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the string parameter.
CVE-2024-38953 1 Phpok 1 Phpok 2026-06-17 N/A 6.1 MEDIUM
phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_control.php file.