Vulnerabilities (CVE)

Filtered by CWE-79
Total 37661 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-2603 1 Salonbookingsystem 1 Salon Booking System 2025-04-18 N/A 6.3 MEDIUM
The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin (or editor depending on Salon booking system WordPress plugin through 9.6.5 configuration) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-31609 1 Bosscms 1 Bosscms 2025-04-18 N/A 7.1 HIGH
Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and footer code fields in code configuration.
CVE-2024-55342 1 Dotnetfoundation 1 Piranha Cms 2025-04-18 N/A 4.7 MEDIUM
A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /manager/media. This PDF can contain malicious JavaScript code, which is executed when a victim user opens or interacts with the PDF in their web browser, leading to a XSS vulnerability.
CVE-2020-22540 1 Codologic 1 Codoforum 2025-04-18 N/A 5.4 MEDIUM
Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive information via crafted payload to Category name component.
CVE-2024-32505 1 Wpmet 1 Elements Kit Elementor Addons 2025-04-18 N/A 6.5 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet Elements kit Elementor addons allows Stored XSS.This issue affects Elements kit Elementor addons: from n/a through 3.0.6.
CVE-2024-4061 1 Ays-pro 1 Survey Maker 2025-04-18 N/A 4.8 MEDIUM
The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-51055 1 Hoosk 1 Hoosk 2025-04-18 N/A 6.5 MEDIUM
An issue Hoosk v1.7.1 allows a remote attacker to execute arbitrary code via a crafted script to the config.php component.
CVE-2023-46950 1 Contribsys 1 Sidekiq 2025-04-18 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted URL to the filter functions.
CVE-2023-46951 1 Contribsys 1 Sidekiq 2025-04-18 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Contribsys Sidekiq v.6.5.8 allows a remote attacker to obtain sensitive information via a crafted payload to the uniquejobs function.
CVE-2025-25949 2025-04-18 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the User ID parameter at /rest/staffResource/update.
CVE-2022-36223 1 Emby 1 Emby 2025-04-18 N/A 6.1 MEDIUM
In Emby Server 4.6.7.0, the playlist name field is vulnerable to XSS stored where it is possible to steal the administrator access token and flip or steal the media server administrator account.
CVE-2024-24511 1 Pkp.sfu 1 Open Journal Systems 2025-04-18 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title component.
CVE-2024-24512 1 Pkp.sfu 1 Open Journal Systems 2025-04-18 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle component.
CVE-2024-30618 1 Chamilo 1 Chamilo Lms 2025-04-18 N/A 6.1 MEDIUM
A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a malicious payload in the 'content' parameter of 'group_topics.php'.
CVE-2024-27525 1 Chamilo 1 Chamilo Lms 2025-04-18 N/A 4.6 MEDIUM
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the home.php component.
CVE-2024-3755 1 Mf Gig Calendar Project 1 Mf Gig Calendar 2025-04-18 N/A 5.4 MEDIUM
The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-33859 1 Logpoint 1 Siem 2025-04-18 N/A 6.1 MEDIUM
An issue was discovered in Logpoint before 7.4.0. HTML code sent through logs wasn't being escaped in the "Interesting Field" Web UI, leading to XSS.
CVE-2025-26153 2025-04-18 N/A 5.4 MEDIUM
A Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into messages, which execute when victims, such as administrators, reply to the message.
CVE-2024-51142 1 Chamilo 1 Chamilo Lms 2025-04-18 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.
CVE-2024-13347 1 Smartdatasoft 1 Essential Wp Real Estate 2025-04-18 N/A 6.8 MEDIUM
The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.