VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2141 CVEsRSS

CVE-2025-64537Critical· 9.3
9mo ago

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could lead to arbitrary code execution. An attacker could exploit this vulnerability by injecting malicious sc…

▾ Midnightadobe · experience_managerEPSS 0.74%via NVD
CVE-2025-34425Medium· 6.1
9mo ago

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the WindowContext parameter of /Mondo/lang/sys/Forms/MAI/compose.aspx

MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the WindowContext parameter of /Mondo/lang/sys/Forms/MAI/compose.aspx. The WindowContext value is not properly sanitized when processed vi…

▾ Sunlitmailenable · mailenableEPSS 0.40%via NVD
CVE-2025-66562Critical· 9.6
9mo ago

TUUI is a desktop MCP client designed as a tool unitary utility integration

TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Execution (RCE) vulnerability exists in Tuui due to an unsafe Cross-Site Scripting (XSS) flaw in the Markdown rendering c…

▾ Midnightaiql · tuuiEPSS 0.52%via NVD
CVE-2025-34257Medium· 5.4
9mo ago

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user creates a task, the defined_name value is stored and later …

▾ Sunlitadvantech · wise-deviceon_serverEPSS 0.26%via NVD
CVE-2025-13739Medium· 6.4
9mo ago

The CryptX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `cryptx` shortcode in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping on user supplied attr…

The CryptX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `cryptx` shortcode in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping on user supplied attr…

▾ SunlitEPSS 0.30%via NVD
CVE-2025-13682Medium· 4.4
9mo ago

The Trail Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping

The Trail Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for aut…

▾ SunlitEPSS 0.24%via NVD
CVE-2025-13678Medium· 6.4
9mo ago

The Thai Lottery Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `thailottery` shortcode in all versions up to, and including, 2.5

The Thai Lottery Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `thailottery` shortcode in all versions up to, and including, 2.5. This is due to insufficient input sanitization and output escaping on th…

▾ SunlitEPSS 0.28%via NVD
CVE-2025-13614High· 8.1
9mo ago

The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cool_tag_cloud' shortcode in all versions up to, and including, 2.29 due to insufficient input sanitization and output escaping on use…

The Cool Tag Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cool_tag_cloud' shortcode in all versions up to, and including, 2.29 due to insufficient input sanitization and output escaping on use…

▾ TwilightEPSS 0.34%via NVD
CVE-2025-12163Medium· 6.4PoC
9mo ago

The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping

The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authe…

▾ TwilightEPSS 0.36%via NVD
CVE-2025-12124Medium· 4.4
9mo ago

The FitVids for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping

The FitVids for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible…

▾ SunlitEPSS 0.18%via NVD
CVE-2025-12417Medium· 6.4
9mo ago

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'surveyfunnel_lite_survey' shortcode in all versions up to, and including, 1.1.5 due to insufficient input sanitizat…

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'surveyfunnel_lite_survey' shortcode in all versions up to, and including, 1.1.5 due to insufficient input sanitizat…

▾ SunlitEPSS 0.22%via NVD
CVE-2025-13939Medium· 6.1
9mo ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Gateway Wireless Controller module) allows Stored XSS.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Gateway Wireless Controller module) allows Stored XSS.

▾ Sunlitwatchguard · firewareEPSS 0.20%via NVD
CVE-2025-13938Medium· 6.1
9mo ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS.

▾ Sunlitwatchguard · firewareEPSS 0.20%via NVD
CVE-2025-13937Medium· 6.1
9mo ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS.

▾ Sunlitwatchguard · firewareEPSS 0.20%via NVD
CVE-2025-13936Medium· 6.1
9mo ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS.

▾ Sunlitwatchguard · firewareEPSS 0.20%via NVD
CVE-2025-14007Low· 2.0
9mo ago

A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1

A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1. This affects an unknown part of the file /admin79f2ec220c7e.php?c=api&m=demo&name=mobile of the component Domain Name Binding Page. The manipulation results in cross site scri…

▾ Sunlitxunruicms · xunruicmsEPSS 0.27%via NVD
CVE-2025-14006Low· 3.5
9mo ago

A security vulnerability has been detected in dayrui XunRuiCMS up to 4.7.1

A security vulnerability has been detected in dayrui XunRuiCMS up to 4.7.1. Affected by this issue is some unknown functionality of the file /admind45f74adbd95.php?c=field&m=add&rname=site&rid=1&page=1 of the component Add Data Validatio…

▾ Sunlitxunruicms · xunruicmsEPSS 0.27%via NVD
CVE-2025-6946Medium· 4.8
9mo ago

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the IPS configuration

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the IPS configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerabil…

▾ Sunlitwatchguard · firewareEPSS 0.24%via NVD
CVE-2025-65027High· 7.6PoC
9mo ago

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. RomM contains multiple unrestricted file upload vulnerabilities that allow authenticated users to upload malic…

▾ Midnightromm.app · rommEPSS 0.33%via NVD
CVE-2025-63401Medium· 5.5
9mo ago

Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives

Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via missing directives

▾ Sunlithcltech · dragonEPSS 0.33%via NVD
CVE-2025-57202Medium· 6.1
9mo ago

A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload int…

A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload int…

▾ Sunlitavtech · dgm1104_firmwareEPSS 0.48%via NVD
CVE-2025-66460Medium· 6.1
10mo ago

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, Lookyloo passed improperly escaped values to cells rendered in datatables using the orthogo…

▾ Sunlitlookyloo · lookylooEPSS 0.19%via NVD
CVE-2025-66459Medium· 6.1
10mo ago

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, a XSS vulnerability can be triggered when a user submits a list of URLs to capture, one of …

▾ Sunlitlookyloo · lookylooEPSS 0.31%via NVD
CVE-2025-66458Medium· 6.1
10mo ago

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, there are multiple XSS due to unsafe use of f-strings in Markup. The issue requires a malic…

▾ Sunlitlookyloo · lookylooEPSS 0.19%via NVD
CVE-2025-13639High· 8.1
10mo ago

Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page

Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low)

▾ Twilightgoogle · chromeEPSS 0.25%via NVD
CVE-2025-13873Medium· 5.4
10mo ago

Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessin…

Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessin…

▾ Sunlitobjectplanet · opinioEPSS 0.20%via NVD
CVE-2025-66312Medium· 5.4
10mo ago

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /ad…

▾ Sunlitgetgrav · grav-plugin-adminEPSS 0.21%via NVD
CVE-2025-66311Medium· 5.4
10mo ago

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /ad…

▾ Sunlitgetgrav · grav-plugin-adminEPSS 0.21%via NVD
CVE-2025-13802Medium· 4.3
10mo ago

A vulnerability was determined in jairiidriss RestaurantWebsite up to e7911f12d035e8e2f9a75e7a28b59e4ef5c1d654

A vulnerability was determined in jairiidriss RestaurantWebsite up to e7911f12d035e8e2f9a75e7a28b59e4ef5c1d654. Impacted is an unknown function of the component Make a Reservation. This manipulation of the argument selected_date causes c…

▾ SunlitEPSS 0.32%via NVD
CVE-2025-13795Low· 2.4
10mo ago

A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c01

A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c01. Affected is an unknown function of the file /student-view.php of the component Edit Student Info Page. This manipu…

▾ SunlitEPSS 0.25%via NVD
CWE-79 vulnerabilities (CVEs) — page 60 · VulnSea