Vulnerabilities (CVE)

Filtered by CWE-79
Total 36252 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-49575 1 Flexense 1 Vx Search 2025-05-21 N/A 7.1 HIGH
A vulnerability has been discovered in VX Search Enterprise affecting version 10.2.14, in Sync Breeze Enterprise Server 10.4.18 version, and in Disk Pulse Enterprise 10.4.18 version, that could allow an attacker to execute persistent XSS through /setup_smtp in smtp_server, smtp_user, smtp_password and smtp_email_address parameters. This vulnerability could allow an attacker to store malicious JavaScript payloads on the system to be triggered when the page loads.
CVE-2023-49572 1 Flexense 1 Vx Search 2025-05-21 N/A 7.1 HIGH
A vulnerability has been discovered in VX Search Enterprise affecting version 10.2.14, and in Disk Pulse Enterprise 10.4.18 version, that could allow an attacker to execute persistent XSS through /setup_odbc in odbc_data_source, odbc_user and odbc_password parameters. This vulnerability could allow an attacker to store malicious JavaScript payloads on the system to be triggered when the page loads.
CVE-2022-40912 1 Etaplighting 1 Etap Safety Manager 2025-05-20 N/A 6.1 MEDIUM
ETAP Lighting International NV ETAP Safety Manager 1.0.0.32 is vulnerable to Cross Site Scripting (XSS). Input passed to the GET parameter 'action' is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site.
CVE-2022-3193 1 Ovirt 1 Ovirt-engine 2025-05-20 N/A 6.1 MEDIUM
An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize the entry, allowing the vulnerability to trigger on the Windows Service Accounts home pages.
CVE-2022-35722 1 Ibm 1 Jazz For Service Management 2025-05-20 N/A 5.4 MEDIUM
IBM Jazz for Service Management is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 231381.
CVE-2022-22387 1 Ibm 1 Application Gateway 2025-05-20 N/A 5.4 MEDIUM
IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 221965.
CVE-2021-41434 1 Oretnom23 1 Expense Management System 2025-05-20 N/A 5.4 MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability exists in version 1.0 of the Expense Management System application that allows for arbitrary execution of JavaScript commands through index.php.
CVE-2025-22383 1 Optimizely 1 Configured Commerce 2025-05-20 N/A 4.6 MEDIUM
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity input validation issue exists in the Commerce B2B application, affecting the Contact Us functionality. This allows visitors to send e-mail messages that could contain unfiltered HTML markup in specific scenarios.
CVE-2022-40879 1 Keking 1 Kkfileview 2025-05-20 N/A 6.1 MEDIUM
kkFileView v4.1.0 is vulnerable to Cross Site Scripting (XSS) via the parameter 'errorMsg.'
CVE-2022-37461 1 Canon 1 Medical Vitrea View 2025-05-20 N/A 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information.
CVE-2022-35137 1 Dgiotcloud 1 Dgiot 2025-05-20 N/A 5.4 MEDIUM
DGIOT Lightweight industrial IoT v4.5.4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
CVE-2025-22388 1 Optimizely 1 Optimizely Cms 2025-05-20 N/A 5.7 MEDIUM
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.22.0. A high-severity Stored Cross-Site Scripting (XSS) vulnerability exists in the CMS, allowing malicious actors to inject and execute arbitrary JavaScript code, potentially compromising user data, escalating privileges, or executing unauthorized actions. The issue exists in multiple areas, including content editing, link management, and file uploads.
CVE-2024-10563 1 Prontotools 1 Woo Cart Count Shortcode 2025-05-20 N/A 5.4 MEDIUM
The WooCommerce Cart Count Shortcode WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2024-12737 1 Wp-base 1 Wp Base Booking Of Appointments\, Services And Events 2025-05-20 N/A 6.1 MEDIUM
The WP BASE Booking of Appointments, Services and Events WordPress plugin before 5.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-13629 1 Csimplifyit 1 Pushbiz 2025-05-20 N/A 6.1 MEDIUM
The pushBIZ WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-13630 1 Mahinsha 1 Newsticker 2025-05-20 N/A 6.1 MEDIUM
The NewsTicker WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-13631 1 Sanditsolution 1 Om Stripe 2025-05-20 N/A 7.1 HIGH
The Om Stripe WordPress plugin through 02.00.00 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-13632 1 Sprintexperts 1 Wp Extra Fields 2025-05-20 N/A 7.1 HIGH
The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-13633 1 Fb-creations 1 Simple Catalogue 2025-05-20 N/A 7.1 HIGH
The Simple catalogue WordPress plugin through 1.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2024-13634 1 Wphobby 1 Post Sync 2025-05-20 N/A 6.1 MEDIUM
The Post Sync WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.