Export limit exceeded: 371382 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 47741 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (47741 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-1401 1 S-a 1 Wp Click Info 2025-04-29 7.1 High
The WP Click Info WordPress plugin through 2.7.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2022-45225 1 Book Store Management System Project 1 Book Store Management System 2025-04-29 6.1 Medium
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the book_title parameter.
CVE-2022-45017 1 Wbce 1 Wbce Cms 2025-04-29 4.8 Medium
A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field.
CVE-2022-45016 1 Wbce 1 Wbce Cms 2025-04-29 4.8 Medium
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field.
CVE-2022-43709 1 Mybb 1 Mybb 2025-04-29 4.9 Medium
MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings.
CVE-2022-38390 1 Ibm 1 Business Automation Workflow 2025-04-29 5.4 Medium
Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 233978.
CVE-2025-3130 1 Drupal 1 Obfuscate 2025-04-29 5.4 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Obfuscate allows Stored XSS.This issue affects Obfuscate: from 0.0.0 before 2.0.1.
CVE-2022-42989 1 Sankhya 1 Sankhya Om 2025-04-29 9 Critical
ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.
CVE-2022-38724 1 Silverstripe 3 Asset Admin, Assets, Framework 2025-04-29 5.4 Medium
Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS.
CVE-2022-38462 1 Silverstripe 1 Framework 2025-04-29 6.1 Medium
Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.
CVE-2022-35501 1 Amasty 1 Blog Pro 2025-04-28 5.4 Medium
Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the duplicate post function.
CVE-2022-35500 1 Amasty 1 Blog Pro 2025-04-28 5.4 Medium
Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality.
CVE-2022-42000 1 Hallowelt 1 Bluespice 2025-04-28 3.3 Low
Cross-site Scripting (XSS) vulnerability in BlueSpiceSocialProfile extension of BlueSpice allows user with comment permissions to inject arbitrary HTML into the comment section of a wikipage.
CVE-2022-4067 1 Librenms 1 Librenms 2025-04-28 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
CVE-2022-45224 1 Web-based Student Clearance System Project 1 Web-based Student Clearance System 2025-04-28 4.8 Medium
Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in Admin/add-admin.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtfullname parameter.
CVE-2022-45223 1 Web-based Student Clearance System Project 1 Web-based Student Clearance System 2025-04-28 4.8 Medium
Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /Admin/add-student.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtfullname parameter.
CVE-2025-29018 1 Codeastro 1 Internet Banking System 2025-04-28 4.8 Medium
A Stored Cross-Site Scripting (XSS) vulnerability exists in the name parameter of pages_add_acc_type.php in Code Astro Internet Banking System 2.0.0.
CVE-2022-42095 1 Backdropcms 1 Backdrop Cms 2025-04-28 4.8 Medium
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.
CVE-2022-3562 1 Librenms 1 Librenms 2025-04-28 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
CVE-2024-46077 2 Mayurik, Online Tours And Travels Management System Project 2 Online Tours And Travels Management System, Online Tours And Travels Management System 2025-04-28 5.4 Medium
itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.