Vulnerabilities (CVE)

Filtered by CWE-79
Total 47481 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-24558 1 Tanstack 1 React-query-next-experimental 2026-06-17 N/A 8.2 HIGH
TanStack Query supplies asynchronous state management, server-state utilities and data fetching for the web. The `@tanstack/react-query-next-experimental` NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this, an attacker would need to either inject malicious input or arrange to have malicious input be returned from an endpoint. To fix this issue, please update to version 5.18.0 or later.
CVE-2024-24556 1 Nearform 1 Urql 2026-06-17 N/A 7.2 HIGH
urql is a GraphQL client that exposes a set of helpers for several frameworks. The `@urql/next` package is vulnerable to XSS. To exploit this an attacker would need to ensure that the response returns `html` tags and that the web-application is using streamed responses (non-RSC). This vulnerability is due to improper escaping of html-like characters in the response-stream. To fix this vulnerability upgrade to version 1.1.1
CVE-2024-24512 1 Pkp.sfu 1 Open Journal Systems 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle component.
CVE-2024-24511 1 Pkp.sfu 1 Open Journal Systems 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title component.
CVE-2024-24510 1 Alinto 1 Sogo 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.
CVE-2024-24507 1 Act-on 1 Act-on 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Act-On 2023 allows a remote attacker to execute arbitrary code via the newUser parameter in the login.jsp component.
CVE-2024-24506 1 Limesurvey 1 Limesurvey 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function.
CVE-2024-24494 1 Remyandrade 1 Daily Habit Tracker 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php components.
CVE-2024-24389 1 Xunruicms 1 Xunruicms 2026-06-17 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in XunRuiCMS up to v4.6.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Column Name parameter.
CVE-2024-24388 1 Xunruicms 1 Xunruicms 2026-06-17 N/A 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in XunRuiCMS versions v4.6.2 and before, allows remote attackers to obtain sensitive information via crafted malicious requests to the background login.
CVE-2024-24276 1 Teamwire 1 Teamwire 2026-06-17 N/A 9.6 CRITICAL
Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the chat name, message preview, username and group name components.
CVE-2024-24275 2 Microsoft, Teamwire 2 Windows, Teamwire 2026-06-17 N/A 9.6 CRITICAL
Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the global search function.
CVE-2024-24160 1 Mrcms 1 Mrcms 2026-06-17 N/A 5.4 MEDIUM
MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.
CVE-2024-24157 1 Sir 1 Gnuboard 2026-06-17 N/A 6.1 MEDIUM
Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py.
CVE-2024-24156 1 Sir 1 Gnuboard 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Gnuboard g6 before Github commit 58c737a263ac0c523592fd87ff71b9e3c07d7cf5, allows remote attackers execute arbitrary code via the wr_content parameter.
CVE-2024-24136 1 Remyandrade 1 Math Game 2026-06-17 N/A 6.1 MEDIUM
The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks.
CVE-2024-24135 1 Remyandrade 1 Product Inventory With Export To Excel 2026-06-17 N/A 6.1 MEDIUM
Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.
CVE-2024-24134 1 Remyandrade 1 Online Food Menu 2026-06-17 N/A 4.8 MEDIUM
Sourcecodester Online Food Menu 1.0 is vulnerable to Cross Site Scripting (XSS) via the 'Menu Name' and 'Description' fields in the Update Menu section.
CVE-2024-24131 1 Superwebmailer 1 Superwebmailer 2026-06-17 N/A 6.1 MEDIUM
SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.
CVE-2024-24130 1 Mail2world 1 Mail2world Webmail 2026-06-17 N/A 6.1 MEDIUM
Mail2World v12 Business Control Center was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Usr parameter at resellercenter/login.asp.