Vulnerabilities (CVE)

Filtered by CWE-79
Total 47426 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-37878 1 Twcms 1 Twcms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary code via the /TWCMS-gh-pages/twcms/runtime/twcms_view/default,index.htm.php" PHP directly echoes parameters input from external sources
CVE-2024-37844 1 Radixiot 1 Mango 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in MangoOS before 5.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-37828 2026-06-17 N/A 4.8 MEDIUM
A stored cross-site scripting (XSS) in Vermeg Agile Reporter v23.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field under the Set Broadcast Message module.
CVE-2024-37803 1 Health Care Hospital Management System Project 1 Health Care Hospital Management System 2026-06-17 N/A 5.4 MEDIUM
Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname and lname parameters under the Staff Info page.
CVE-2024-37800 1 Code-projects 1 Restaurant Reservation System 2026-06-17 N/A 6.1 MEDIUM
CodeProjects Restaurant Reservation System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Date parameter at index.php.
CVE-2024-37798 1 Phpgurukul 1 Beauty Parlour Management System 2026-06-17 N/A 5.9 MEDIUM
Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input field.
CVE-2024-37783 2026-06-17 N/A 5.4 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in Gladinet CentreStack v13.12.9934.54690 allows attackers to inject malicious JavaScript into the web browser of a victim via the sessionId parameter at /portal/ForgotPassword.aspx.
CVE-2024-37764 1 Machform 1 Machform 2026-06-17 N/A 5.4 MEDIUM
MachForm up to version 19 is affected by an authenticated stored cross-site scripting.
CVE-2024-37763 1 Machform 1 Machform 2026-06-17 N/A 5.4 MEDIUM
MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.
CVE-2024-37741 1 Openplcproject 2 Openplc V3, Openplc V3 Firmware 2026-06-17 N/A 5.4 MEDIUM
OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.
CVE-2024-37732 1 Anchorcms 1 Anchor Cms 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file.
CVE-2024-37680 1 Finesoft Project 1 Finesoft 2026-06-17 N/A 6.1 MEDIUM
Hangzhou Meisoft Information Technology Co., Ltd. FineSoft <=8.0 is affected by Cross Site Scripting (XSS) which allows remote attackers to execute arbitrary code. Enter any account and password, click Login, the page will report an error, and a controllable parameter will appear at the URL:weburl.
CVE-2024-37679 1 Finesoft Project 1 Finesoft 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp parameter.
CVE-2024-37629 1 Summernote 1 Summernote 2026-06-17 N/A 6.1 MEDIUM
SummerNote v0.9.1 is vulnerable to Cross Site Scripting (XSS) via the Code View Function.
CVE-2024-37625 1 Zhimengzhel 1 Ibarn 2026-06-17 N/A 6.1 MEDIUM
zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /index.php.
CVE-2024-37624 1 Rockoa 1 Xinhu 2026-06-17 N/A 6.1 MEDIUM
Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /chajian/inputChajian.php. component.
CVE-2024-37623 1 Rockoa 1 Xinhu 2026-06-17 N/A 6.1 MEDIUM
Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /kaoqin/tpl_kaoqin_locationchange.html component.
CVE-2024-37622 1 Rockoa 1 Xinhu 2026-06-17 N/A 6.1 MEDIUM
Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter at /flow/flow.php.
CVE-2024-37620 2026-06-17 N/A 6.1 MEDIUM
PHPVOD v4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /view/admin/view.php.
CVE-2024-37619 1 Strongshop 1 Strongshop 2026-06-17 N/A 6.1 MEDIUM
StrongShop v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the spec_group_id parameter at /spec/index.blade.php.