Export limit exceeded: 376074 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 48067 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (48067 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-48986 1 Cusg 1 Content Management System 2025-03-20 6.1 Medium
Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the users.php component.
CVE-2022-4286 1 Br-automation 1 Automation Runtime 2025-03-20 6.1 Medium
A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the context of the users browser session.
CVE-2019-15870 1 Scriptsbundle 1 Carspot 2025-03-20 N/A
The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.
CVE-2024-40746 1 Hikashop 1 Hikashop 2025-03-20 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload in the `description` parameter of any product. The `description `parameter is not sanitised in the backend.
CVE-2024-21730 1 Joomla 1 Joomla\! 2025-03-20 5.4 Medium
The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.
CVE-2024-39457 1 Cybozu 1 Garoon 2025-03-19 5.4 Medium
Cybozu Garoon 6.0.0 to 6.0.1 contains a cross-site scripting vulnerability in PDF preview. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user’s web browser.
CVE-2024-38466 1 Guoxinled 1 Synthesis Image System 2025-03-19 9.8 Critical
Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.
CVE-2019-13029 1 Vanderbilt 1 Redcap 2025-03-19 N/A
Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9 before 9.1.2 allow an attacker to inject arbitrary malicious HTML or JavaScript code into a user's web browser.
CVE-2018-6867 1 Alibaba Clone Script Project 1 Alibaba Clone Script 2025-03-19 N/A
Cross Site Scripting (XSS) exists in PHP Scripts Mall Alibaba Clone Script 1.0.2 via a profile parameter.
CVE-2024-21686 1 Atlassian 2 Confluence Data Center, Confluence Server 2025-03-19 8.7 High
This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server. This Stored XSS vulnerability, with a CVSS Score of 7.3, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, high impact to integrity, no impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions listed on this CVE See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html). You can download the latest version of Confluence Data Center and Server from the download center (https://www.atlassian.com/software/confluence/download-archives). This vulnerability was reported via our Bug Bounty program.
CVE-2023-25763 1 Jenkins 1 Email Extension 2025-03-19 5.4 Medium
Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control affected fields.
CVE-2023-25762 2 Jenkins, Redhat 3 Pipeline\, Ocp Tools, Openshift 2025-03-19 5.4 Medium
Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pipeline Snippet Generator, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control job names.
CVE-2020-19825 1 Kimai 1 Kimai 2025-03-19 9.6 Critical
Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.
CVE-2024-50656 1 Angeljudesuarez 1 Placement Management System 2025-03-19 6.1 Medium
itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.
CVE-2024-44684 1 Tpmecms 1 Tpmecms 2025-03-19 6.1 Medium
TpMeCMS 1.3.3.2 is vulnerable to Cross Site Scripting (XSS) in /h.php/page?ref=addtabs via the "Title," "Images," and "Content" fields.
CVE-2024-41599 1 Ruoyi 1 Ruoyi 2025-03-19 6.1 Medium
Cross Site Scripting vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the file upload method
CVE-2024-39125 1 Roundup-tracker 1 Roundup 2025-03-19 5.4 Medium
Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.
CVE-2023-43971 1 Lizhipay 1 Acg-faka 2025-03-19 6.1 Medium
Cross Site Scripting vulnerability in ACG-faka v1.1.7 allows a remote attacker to execute arbitrary code via the encode parameter in Index.php.
CVE-2022-45543 1 Discuz 1 Discuzx 2025-03-19 6.1 Medium
Cross site scripting (XSS) vulnerability in DiscuzX 3.4 allows attackers to execute arbitrary code via the datetline, title, tpp, or username parameters via the audit search.
CVE-2023-25764 1 Jenkins 1 Email Extension 2025-03-19 5.4 Medium
Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generated during template rendering, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or change custom email templates.