Total
37016 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2025-40723 | 2025-07-03 | N/A | N/A | ||
Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a stored XSS due to lack of proper validation of user input, through the footer_text and announcement parameters in config.php. | |||||
CVE-2025-20310 | 2025-07-03 | N/A | 6.1 MEDIUM | ||
A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web UI does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To successfully exploit this vulnerability, an attacker would need valid agent credentials. | |||||
CVE-2024-33210 | 1 Flatpress | 1 Flatpress | 2025-07-03 | N/A | 5.4 MEDIUM |
A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users. | |||||
CVE-2024-45960 | 1 Tribalsystems | 1 Zenario | 2025-07-03 | N/A | 4.8 MEDIUM |
Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the website, it can trigger a Cross Site Scripting (XSS) attack. | |||||
CVE-2024-45964 | 1 Tribalsystems | 1 Zenario | 2025-07-03 | N/A | 4.8 MEDIUM |
Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field. | |||||
CVE-2024-45965 | 1 Contao | 1 Contao | 2025-07-03 | N/A | 6.4 MEDIUM |
Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6. | |||||
CVE-2024-46409 | 1 Seeddms | 1 Seeddms | 2025-07-03 | N/A | 5.4 MEDIUM |
A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter in the Calendar page. | |||||
CVE-2024-42901 | 1 Limesurvey | 1 Limesurvey | 2025-07-03 | N/A | 4.8 MEDIUM |
A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted CSV file. | |||||
CVE-2024-44085 | 1 Onlyoffice | 1 Onlyoffice | 2025-07-03 | N/A | 6.1 MEDIUM |
ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoked function expression (IIFE) for a macro. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446 and CVE-2023-50883. | |||||
CVE-2022-40490 | 1 Tiny File Manager Project | 1 Tiny File Manager | 2025-07-03 | N/A | 4.8 MEDIUM |
Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing file. | |||||
CVE-2024-57599 | 1 Douco | 1 Douphp | 2025-07-03 | N/A | 4.8 MEDIUM |
Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in /admin/article.php | |||||
CVE-2024-54795 | 1 Eng | 1 Spagobi | 2025-07-03 | N/A | 5.4 MEDIUM |
SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function. | |||||
CVE-2024-33297 | 1 Microweber | 1 Microweber | 2025-07-03 | N/A | 4.7 MEDIUM |
Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function | |||||
CVE-2024-33298 | 1 Microweber | 1 Microweber | 2025-07-03 | N/A | 6.1 MEDIUM |
Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup | |||||
CVE-2024-33299 | 1 Microweber | 1 Microweber | 2025-07-03 | N/A | 4.7 MEDIUM |
Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users | |||||
CVE-2024-53620 | 1 Spip | 1 Spip | 2025-07-03 | N/A | 4.8 MEDIUM |
A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter. | |||||
CVE-2024-55239 | 1 Portabilis | 1 I-educar | 2025-07-03 | N/A | 5.4 MEDIUM |
A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows attacker to craft malicious urls with arbitrary javascript in the 'titulo_documento' parameter. | |||||
CVE-2025-49262 | 1 Sinaextra | 1 Sina Extension For Elementor | 2025-07-02 | N/A | 7.6 HIGH |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shaonsina Sina Extension for Elementor allows Stored XSS. This issue affects Sina Extension for Elementor: from n/a through 3.6.1. | |||||
CVE-2025-5291 | 1 Averta | 1 Master Slider | 2025-07-02 | N/A | 6.4 MEDIUM |
The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's masterslider_pb and ms_slide shortcodes in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |||||
CVE-2025-4955 | 1 Amauri | 1 Tarteaucitron.io | 2025-07-02 | N/A | 4.7 MEDIUM |
The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks. |