Total
47481 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-27729 | 1 Friendica | 1 Friendica | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the location parameter of the calendar event feature. | |||||
| CVE-2024-27728 | 1 Friendica | 1 Friendica | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the text parameter of the babel debug feature. | |||||
| CVE-2024-27719 | 1 Rems | 1 Faq Management System | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross site scripting (XSS) vulnerability in rems FAQ Management System v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the Frequently Asked Question field in the Add FAQ function. | |||||
| CVE-2024-27706 | 2026-06-17 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in Huly Platform v.0.6.202 allows attackers to execute arbitrary code via upload of crafted SVG file to issues. | |||||
| CVE-2024-27703 | 1 Leantime | 1 Leantime | 2026-06-17 | N/A | 5.4 MEDIUM |
| Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do title parameter. | |||||
| CVE-2024-27684 | 1 Dlink | 2 Go-rt-ac750, Go-rt-ac750 Firmware | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Cross-site scripting (XSS) vulnerability in dlapn.cgi, dldongle.cgi, dlcfg.cgi, fwup.cgi and seama.cgi in D-Link GORTAC750_A1_FW_v101b03 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | |||||
| CVE-2024-27680 | 1 Flusity | 1 Flusity | 2026-06-17 | N/A | 6.1 MEDIUM |
| Flusity-CMS v2.33 is vulnerable to Cross Site Scripting (XSS) in the "Contact form." | |||||
| CVE-2024-27668 | 1 Flusity | 1 Flusity | 2026-06-17 | N/A | 6.1 MEDIUM |
| Flusity-CMS v2.33 is affected by: Cross Site Scripting (XSS) in 'Custom Blocks.' | |||||
| CVE-2024-27665 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| Unifiedtransform v2.X is vulnerable to Stored Cross-Site Scripting (XSS) via file upload feature in Syllabus module. | |||||
| CVE-2024-27626 | 1 Dotclear | 1 Dotclear | 2026-06-17 | N/A | 6.1 MEDIUM |
| A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists within the Search functionality of the Admin Panel. | |||||
| CVE-2024-27625 | 1 Cmsmadesimple | 1 Cms Made Simple | 2026-06-17 | N/A | 4.8 MEDIUM |
| CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manager module of the admin panel. Specifically, the issue arises due to inadequate sanitization of user input in the "New directory" field. | |||||
| CVE-2024-27609 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Bonita before 2023.2-u2 allows stored XSS via a UI screen in the administration panel. | |||||
| CVE-2024-27593 | 2026-06-17 | N/A | 5.4 MEDIUM | ||
| A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the filter name field. This vulnerability has been fixed in version 3.23.0. | |||||
| CVE-2024-27558 | 1 Codelyfe | 1 Stupid Simple Cms | 2026-06-17 | N/A | 6.1 MEDIUM |
| Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings. | |||||
| CVE-2024-27525 | 1 Chamilo | 1 Chamilo Lms | 2026-06-17 | N/A | 4.6 MEDIUM |
| Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the home.php component. | |||||
| CVE-2024-27524 | 1 Chamilo | 1 Chamilo Lms | 2026-06-17 | N/A | 7.1 HIGH |
| Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the new_ticket.php component. | |||||
| CVE-2024-27517 | 1 Webasyst | 1 Webasyst | 2026-06-17 | N/A | 5.4 MEDIUM |
| Webasyst 2.9.9 has a Cross-Site Scripting (XSS) vulnerability, Attackers can create blogs containing malicious code after gaining blog permissions. | |||||
| CVE-2024-27499 | 1 Webkul | 1 Bagisto | 2026-06-17 | N/A | 6.5 MEDIUM |
| Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option. | |||||
| CVE-2024-27477 | 1 Leantime | 1 Leantime | 2026-06-17 | N/A | 6.1 MEDIUM |
| In Leantime 3.0.6, a Cross-Site Scripting vulnerability exists within the ticket creation and modification functionality, allowing attackers to inject malicious JavaScript code into the title field of tickets (also known as to-dos). This stored XSS vulnerability can be exploited to perform Server-Side Request Forgery (SSRF) attacks. | |||||
| CVE-2024-27443 | 1 Zimbra | 1 Collaboration | 2026-06-17 | N/A | 6.1 MEDIUM |
| An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code. | |||||
