Vulnerabilities (CVE)

Filtered by CWE-79
Total 47481 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-27729 1 Friendica 1 Friendica 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the location parameter of the calendar event feature.
CVE-2024-27728 1 Friendica 1 Friendica 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the text parameter of the babel debug feature.
CVE-2024-27719 1 Rems 1 Faq Management System 2026-06-17 N/A 6.1 MEDIUM
A cross site scripting (XSS) vulnerability in rems FAQ Management System v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the Frequently Asked Question field in the Add FAQ function.
CVE-2024-27706 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Huly Platform v.0.6.202 allows attackers to execute arbitrary code via upload of crafted SVG file to issues.
CVE-2024-27703 1 Leantime 1 Leantime 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do title parameter.
CVE-2024-27684 1 Dlink 2 Go-rt-ac750, Go-rt-ac750 Firmware 2026-06-17 N/A 6.1 MEDIUM
A Cross-site scripting (XSS) vulnerability in dlapn.cgi, dldongle.cgi, dlcfg.cgi, fwup.cgi and seama.cgi in D-Link GORTAC750_A1_FW_v101b03 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
CVE-2024-27680 1 Flusity 1 Flusity 2026-06-17 N/A 6.1 MEDIUM
Flusity-CMS v2.33 is vulnerable to Cross Site Scripting (XSS) in the "Contact form."
CVE-2024-27668 1 Flusity 1 Flusity 2026-06-17 N/A 6.1 MEDIUM
Flusity-CMS v2.33 is affected by: Cross Site Scripting (XSS) in 'Custom Blocks.'
CVE-2024-27665 2026-06-17 N/A 5.4 MEDIUM
Unifiedtransform v2.X is vulnerable to Stored Cross-Site Scripting (XSS) via file upload feature in Syllabus module.
CVE-2024-27626 1 Dotclear 1 Dotclear 2026-06-17 N/A 6.1 MEDIUM
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of the Admin Panel.
CVE-2024-27625 1 Cmsmadesimple 1 Cms Made Simple 2026-06-17 N/A 4.8 MEDIUM
CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manager module of the admin panel. Specifically, the issue arises due to inadequate sanitization of user input in the "New directory" field.
CVE-2024-27609 2026-06-17 N/A 6.5 MEDIUM
Bonita before 2023.2-u2 allows stored XSS via a UI screen in the administration panel.
CVE-2024-27593 2026-06-17 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the filter name field. This vulnerability has been fixed in version 3.23.0.
CVE-2024-27558 1 Codelyfe 1 Stupid Simple Cms 2026-06-17 N/A 6.1 MEDIUM
Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings.
CVE-2024-27525 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 4.6 MEDIUM
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the home.php component.
CVE-2024-27524 1 Chamilo 1 Chamilo Lms 2026-06-17 N/A 7.1 HIGH
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the new_ticket.php component.
CVE-2024-27517 1 Webasyst 1 Webasyst 2026-06-17 N/A 5.4 MEDIUM
Webasyst 2.9.9 has a Cross-Site Scripting (XSS) vulnerability, Attackers can create blogs containing malicious code after gaining blog permissions.
CVE-2024-27499 1 Webkul 1 Bagisto 2026-06-17 N/A 6.5 MEDIUM
Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.
CVE-2024-27477 1 Leantime 1 Leantime 2026-06-17 N/A 6.1 MEDIUM
In Leantime 3.0.6, a Cross-Site Scripting vulnerability exists within the ticket creation and modification functionality, allowing attackers to inject malicious JavaScript code into the title field of tickets (also known as to-dos). This stored XSS vulnerability can be exploited to perform Server-Side Request Forgery (SSRF) attacks.
CVE-2024-27443 1 Zimbra 1 Collaboration 2026-06-17 N/A 6.1 MEDIUM
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.