Total
47481 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-27136 | 1 Apache | 1 Jspwiki | 2026-06-17 | N/A | 6.1 MEDIUM |
| XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later. | |||||
| CVE-2024-27133 | 1 Lfprojects | 1 Mlflow | 2026-06-17 | N/A | 7.5 HIGH |
| Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running the recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over dataset table fields. | |||||
| CVE-2024-27132 | 1 Lfprojects | 1 Mlflow | 2026-06-17 | N/A | 7.5 HIGH |
| Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook. The vulnerability stems from lack of sanitization over template variables. | |||||
| CVE-2024-27126 | 1 Qnap | 1 Notes Station 3 | 2026-06-17 | N/A | 6.3 MEDIUM |
| A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: Notes Station 3 3.9.6 and later | |||||
| CVE-2024-27125 | 1 Qnap | 1 Helpdesk | 2026-06-17 | N/A | 3.5 LOW |
| A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following version: Helpdesk 3.3.1 and later | |||||
| CVE-2024-27122 | 1 Qnap | 1 Notes Station 3 | 2026-06-17 | N/A | 6.3 MEDIUM |
| A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: Notes Station 3 3.9.6 and later | |||||
| CVE-2024-27104 | 1 Glpi-project | 1 Glpi | 2026-06-17 | N/A | 4.5 MEDIUM |
| GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. A user with rights to create and share dashboards can build a dashboard containing javascript code. Any user that will open this dashboard will be subject to an XSS attack. This issue has been patched in version 10.0.13. | |||||
| CVE-2024-27103 | 1 Pinterest | 1 Querybook | 2026-06-17 | N/A | 6.1 MEDIUM |
| Querybook is a Big Data Querying UI. When a user searches for their queries, datadocs, tables and lists, the search result is marked and highlighted, and this feature uses dangerouslySetInnerHTML which means that if the highlighted result has an XSS payload it will trigger. While the input to dangerouslySetInnerHTML is not sanitized for the data inside of queries which leads to an XSS vulnerability. During the "query auto-suggestion" the name of the suggested tables are set with innerHTML which leads to the XSS vulnerability. A patch to rectify this issue has been introduced in Querybook version 3.31.2. | |||||
| CVE-2024-27095 | 1 Decidim | 1 Decidim | 2026-06-17 | N/A | 5.4 MEDIUM |
| Decidim is a participatory democracy framework. The admin panel is subject to potential XSS attach in case the attacker manages to modify some records being uploaded to the server. This vulnerability is fixed in 0.27.6 and 0.28.1. | |||||
| CVE-2024-27092 | 1 Hoppscotch | 1 Hoppscotch | 2026-06-17 | N/A | 5.4 MEDIUM |
| Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad actors can send emails with Spoofed Content as Hoppscotch. Part of payload (external link) is presented in clickable form - easier to achieve own goals by malicious actors. This issue is fixed in 2023.12.6. | |||||
| CVE-2024-27091 | 1 Geosolutionsgroup | 1 Geonode | 2026-06-17 | N/A | 6.1 MEDIUM |
| GeoNode is a geospatial content management system, a platform for the management and publication of geospatial data. An issue exists within GEONODE where the current rich text editor is vulnerable to Stored XSS. The applications cookies are set securely, but it is possible to retrieve a victims CSRF token and issue a request to change another user's email address to perform a full account takeover. Due to the script element not impacting the CORS policy, requests will succeed. This vulnerability is fixed in 4.2.3. | |||||
| CVE-2024-27087 | 1 Getkirby | 1 Kirby | 2026-06-17 | N/A | 4.6 MEDIUM |
| Kirby is a content management system. The new link field introduced in Kirby 4 allows several different link types that each validate the entered link to the relevant URL format. It also includes a "Custom" link type for advanced use cases that don't fit any of the pre-defined link formats. As the "Custom" link type is meant to be flexible, it also allows the javascript: URL scheme. In some use cases this can be intended, but it can also be misused by attackers to execute arbitrary JavaScript code when a user or visitor clicks on a link that is generated from the contents of the link field. This vulnerability is patched in 4.1.1. | |||||
| CVE-2024-27083 | 1 Dpgaspar | 1 Flask-appbuilder | 2026-06-17 | N/A | 4.3 MEDIUM |
| Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code that would get executed on the user's browser. This issue was introduced on 4.1.4 and patched on 4.2.1. | |||||
| CVE-2024-27082 | 1 Cacti | 1 Cacti | 2026-06-17 | N/A | 7.6 HIGH |
| Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site scripting where malicious scripts are permanently stored on a target server and served to users who access a particular page. Version 1.2.27 contains a patch for the issue. | |||||
| CVE-2024-26557 | 1 Codiad | 1 Codiad | 2026-06-17 | N/A | 5.4 MEDIUM |
| Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter. | |||||
| CVE-2024-26542 | 1 Bonitasoft | 1 Bonita Web | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting vulnerability in Bonitasoft, S.A v.7.14. and fixed in v.9.0.2, 8.0.3, 7.15.7, 7.14.8 allows attackers to execute arbitrary code via a crafted payload to the Groups Display name field. | |||||
| CVE-2024-26521 | 2026-06-17 | N/A | 4.8 MEDIUM | ||
| HTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted payload to the english.php component. | |||||
| CVE-2024-26517 | 1 Rems | 1 School Task Manager | 2026-06-17 | N/A | 9.1 CRITICAL |
| SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the delete-task.php component. | |||||
| CVE-2024-26495 | 1 Friendica | 1 Friendica | 2026-06-17 | N/A | 6.1 MEDIUM |
| Cross Site Scripting (XSS) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the BBCode tags in the post content and post comments function. | |||||
| CVE-2024-26491 | 1 Flusity | 1 Flusity | 2026-06-17 | N/A | 6.1 MEDIUM |
| A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Media Gallery with description' module of flusity-CMS v2.33 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Gallery name text field. | |||||
