VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2143 CVEsRSS

CVE-2025-13802Medium· 4.3
10mo ago

A vulnerability was determined in jairiidriss RestaurantWebsite up to e7911f12d035e8e2f9a75e7a28b59e4ef5c1d654

A vulnerability was determined in jairiidriss RestaurantWebsite up to e7911f12d035e8e2f9a75e7a28b59e4ef5c1d654. Impacted is an unknown function of the component Make a Reservation. This manipulation of the argument selected_date causes c…

▾ SunlitEPSS 0.32%via NVD
CVE-2025-13795Low· 2.4
10mo ago

A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c01

A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c01. Affected is an unknown function of the file /student-view.php of the component Edit Student Info Page. This manipu…

▾ SunlitEPSS 0.25%via NVD
CVE-2025-13793Medium· 4.3
10mo ago

A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e

A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the component GET Parameter …

▾ SunlitEPSS 0.32%via NVD
CVE-2025-13784Low· 2.4
10mo ago

A weakness has been identified in yungifez Skuul School Management System up to 2.6.5

A weakness has been identified in yungifez Skuul School Management System up to 2.6.5. This vulnerability affects unknown code of the file /dashboard/schools/1/edit of the component SVG File Handler. This manipulation causes cross site s…

▾ Sunlityungifez · skuulEPSS 0.28%via NVD
CVE-2025-64130Critical· 9.8
10mo ago

Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to execute arbitrary JavaScript on the victim's browser.

Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to execute arbitrary JavaScript on the victim's browser.

▾ MidnightEPSS 0.90%via NVD
CVE-2025-55124Medium· 6.1
10mo ago

Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.

Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.41%via NVD
CVE-2025-55123Medium· 5.4
10mo ago

Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.

Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.45%via NVD
CVE-2025-52668Medium· 5.4
10mo ago

Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.

Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.53%via NVD
CVE-2025-52667Medium· 5.4
10mo ago

Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a logged in manager user.

Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a logged in manager user.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.37%via NVD
CVE-2025-48987Medium· 6.1
10mo ago

Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.

Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.51%via NVD
CVE-2025-63892Medium· 6.8PoC
10mo ago

A vulnerability was determined in SourceCodester Student Grades Management System 1.0

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_classroom of the file /classroom.php of the component My Classrooms Management Page. This manipulation of the argument…

▾ Twilightremyandrade · student_grades_management_systemEPSS 0.36%via NVD
CVE-2023-7314Medium· 5.4
11mo ago

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script i…

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script i…

▾ Sunlitnagios · nagios_xiEPSS 0.45%via NVD
CVE-2023-7313Medium· 5.4
11mo ago

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modifications tool

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modifications tool. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in t…

▾ Sunlitnagios · nagios_xiEPSS 0.45%via NVD
CVE-2025-64289Medium· 5.9
11mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows Stored XSS.This issue affects Premmerce Product Search for W…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows Stored XSS.This issue affects Premmerce Product Search for W…

▾ SunlitPremmerce · premmerce-searchEPSS 0.17%via NVD
CVE-2025-34318None
11mo ago

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code through the TLS_HOSTNAME, UPSTREAM_USER, UPSTREAM_PASSWOR…

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code through the TLS_HOSTNAME, UPSTREAM_USER, UPSTREAM_PASSWOR…

▾ SunlitEPSS 0.48%via NVD
CVE-2025-34316Medium· 5.4
11mo ago

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code through the txt_mailuser and txt_mailpass parameters when…

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code through the txt_mailuser and txt_mailpass parameters when…

▾ Sunlitipfire · ipfireEPSS 0.45%via NVD
CVE-2025-34315Medium· 5.4
11mo ago

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code through the REMOTELOG_ADDR parameter when updating the re…

IPFire versions prior to 2.29 (Core Update 198) contain a stored cross-site scripting (XSS) vulnerability that allows an authenticated attacker to inject arbitrary JavaScript code through the REMOTELOG_ADDR parameter when updating the re…

▾ Sunlitipfire · ipfireEPSS 0.45%via NVD
CVE-2025-31366Medium· 4.7
11mo ago

An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all…

An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all…

▾ Sunlitfortinet · fortiproxyEPSS 0.40%via NVD
CVE-2025-60967High· 7.3
11mo ago

Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00 allows attackers to gain sensitive information.

Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00 allows attackers to gain sensitive information.

▾ Twilightendruntechnologies · sonoma_d12_firmwareEPSS 0.26%via NVD
CVE-2025-60961Medium· 6.1
11mo ago

Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information, and possibly other unspecified impacts.

Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information, and possibly other unspecified impacts.

▾ Sunlitendruntechnologies · sonoma_d12_firmwareEPSS 0.19%via NVD
CVE-2025-60958High· 7.3
11mo ago

Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information.

Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information.

▾ Twilightendruntechnologies · sonoma_d12_firmwareEPSS 0.26%via NVD
CVE-2021-42193Medium· 6.1
12mo ago

nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]

nopCommerce 4.40.3 is vulnerable to XSS in the Product Name at /Admin/Product/Edit/[id]. Each time a user views the product in the shop, the XSS payload fires.

▾ Sunlitnopcommerce · nopcommerceEPSS 0.23%via NVD
CVE-2025-9353Medium· 6.4
1y ago

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to insufficient input sanitization and output escaping

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to insufficient input sanitization and output escaping. This makes it possible f…

▾ SunlitEPSS 0.33%via NVD
CVE-2025-43779Medium· 6.1
1y ago

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript cod…

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 allows a remote authenticated attacker to inject JavaScript cod…

▾ Sunlitliferay · digital_experience_platformEPSS 0.23%via NVD
CVE-2025-9798High· 8.9
1y ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Software Inc

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Software Inc. Netigma allows Stored XSS. This issue affects Netigma: from 6.3.3 before 6.3.5 V8.

▾ TwilightEPSS 0.27%via NVD
CVE-2025-55887Medium· 6.1PoC
1y ago

Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD

Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD. The vulnerability exists in the transactionID GET parameter on the transaction confirmation page. Due to improper input validation and output en…

▾ Twilightard · gec_en_ligneEPSS 0.35%via NVD
CVE-2025-55888High· 7.3PoC
1y ago

Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD

Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can intercept the Ajax response and inject malicious JavaScript into the accountName field. This input is not properly s…

▾ Midnightard · gec_en_ligneEPSS 0.44%via NVD
CVE-2025-37122Medium· 6.1
1y ago

A vulnerability in the web-based management interface of network access control services could allow an unauthenticated remote attacker to conduct a Reflected Cross-Site Scripting (XSS) attack

A vulnerability in the web-based management interface of network access control services could allow an unauthenticated remote attacker to conduct a Reflected Cross-Site Scripting (XSS) attack. Successful exploitation could allow an atta…

▾ SunlitEPSS 0.25%via NVD
CVE-2025-10614Medium· 4.3
1y ago

A vulnerability was determined in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0 on COVID

A vulnerability was determined in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0 on COVID. This affects an unknown function of the file /print_reports_prev.php. Executing manipulation of the argument profile_id can…

▾ Sunlitemiloi · e-logbook_with_health_monitoring_system_for_covid-19EPSS 0.35%via NVD
CVE-2025-10605Medium· 4.3
1y ago

A security flaw has been discovered in Portabilis i-Educar up to 2.10

A security flaw has been discovered in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /agenda_preferencias.php. The manipulation of the argument tipoacao results in cross site scripting. The attack ma…

▾ Sunlitportabilis · i-educarEPSS 0.40%via NVD
CWE-79 vulnerabilities (CVEs) — page 61 · VulnSea