VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2143 CVEsRSS

CVE-2022-33009Medium· 4.8
4y ago

A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploading a crafted PDF file.

A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploading a crafted PDF file.

▾ Sunlitlightcms_project · lightcmsEPSS 0.52%via NVD
CVE-2020-21161Medium· 6.1
4y ago

Cross Site Scripting (XSS) vulnerability in Ruckus Wireless ZoneDirector 9.8.3.0.

Cross Site Scripting (XSS) vulnerability in Ruckus Wireless ZoneDirector 9.8.3.0.

▾ Sunlitruckuswireless · zonedirector_firmwareEPSS 0.71%via NVD
CVE-2020-27509Medium· 5.4
4y ago

Persistent XSS in Galaxkey Secure Mail Client in Galaxkey up to 5.6.11.5 allows an attacker to perform an account takeover by intercepting the HTTP Post request when sending an email and injecting a specially crafted XSS payload in the '…

Persistent XSS in Galaxkey Secure Mail Client in Galaxkey up to 5.6.11.5 allows an attacker to perform an account takeover by intercepting the HTTP Post request when sending an email and injecting a specially crafted XSS payload in the '…

▾ Sunlitgalaxkey · galaxkeyEPSS 0.58%via NVD
CVE-2022-25585Medium· 5.4
4y ago

Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.

Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.

▾ Sunlitunioncms_project · unioncmsEPSS 0.43%via NVD
CVE-2021-45026Medium· 6.1PoC
4y ago

ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).

ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS).

▾ Twilightrocketsoftware · ags-zenaEPSS 1.2%via NVD
CVE-2021-41663Medium· 6.1
4y ago

A cross-site scripting (XSS) vulnerability exists in Mini CMS V1.11

A cross-site scripting (XSS) vulnerability exists in Mini CMS V1.11. The vulnerability exists in the article upload: post-edit.php page.

▾ Sunlit1234n · minicmsEPSS 0.77%via NVD
CVE-2022-24238Medium· 6.1
4y ago

ACEweb Online Portal 3.5.065 was discovered to contain a cross-site scripting (XSS) vulnerability via the txtNmName1 parameter in person.awp.

ACEweb Online Portal 3.5.065 was discovered to contain a cross-site scripting (XSS) vulnerability via the txtNmName1 parameter in person.awp.

▾ Sunlitaceware · aceweb_online_portalEPSS 0.56%via NVD
CVE-2022-29005Medium· 6.1PoC
4y ago

Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname o…

Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname o…

▾ Twilightphpgurukul · online_birth_certificate_systemEPSS 2.2%via NVD
CVE-2022-29004Medium· 6.1PoC
4y ago

Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.

Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.

▾ Twilightphpgurukul · e-diary_management_systemEPSS 2.9%via NVD
CVE-2020-22987Medium· 6.1
4y ago

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task.

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task.

▾ Sunlitmicrostrategy · microstrategy_web_sdkEPSS 1.5%via NVD
CVE-2020-22986Medium· 6.1
4y ago

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the searchString parameter to the wikiScrapper task.

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the searchString parameter to the wikiScrapper task.

▾ Sunlitmicrostrategy · microstrategy_web_sdkEPSS 1.6%via NVD
CVE-2020-22985Medium· 6.1
4y ago

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.

▾ Sunlitmicrostrategy · microstrategy_web_sdkEPSS 1.6%via NVD
CVE-2020-22984Medium· 6.1
4y ago

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via key parameter to the getGoogleExtraConfig task.

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via key parameter to the getGoogleExtraConfig task.

▾ Sunlitmicrostrategy · microstrategy_web_sdkEPSS 1.6%via NVD
CVE-2022-28078Medium· 6.1PoC
4y ago

Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.

Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.

▾ Twilighthome_owners_collection_management_system_project · home_owners_collection_management_systemEPSS 1.1%via NVD
CVE-2022-28077Medium· 6.1PoC
4y ago

Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.

Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.

▾ Twilighthome_owners_collection_management_system_project · home_owners_collection_management_systemEPSS 0.81%via NVD
CVE-2021-43712Medium· 5.4
4y ago

Stored XSS in Add New Employee Form in Sourcecodester Employee Daily Task Management System 1.0 Allows Remote Attacker to Inject/Store Arbitrary Code via the Name Field.

Stored XSS in Add New Employee Form in Sourcecodester Employee Daily Task Management System 1.0 Allows Remote Attacker to Inject/Store Arbitrary Code via the Name Field.

▾ Sunlitemployee_daily_task_management_system_project · employee_daily_task_management_systemEPSS 0.69%via NVD
CVE-2021-31674Medium· 6.1PoC
4y ago

Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.

Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacker to execute javascript code via undefine enum constant.

▾ Twilightcyclos · cyclosEPSS 3.9%via NVD
CVE-2021-31673Medium· 6.1PoC
4y ago

A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter.

A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remote attackers to inject arbitrary web script or HTML via the groupId parameter.

▾ Twilightcyclos · cyclosEPSS 2.6%via NVD
CVE-2022-28102Medium· 5.4
4y ago

A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php.

A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php.

▾ Sunlitphp_mysql_admin_panel_generator_project · php_mysql_admin_panel_generatorEPSS 0.49%via NVD
CVE-2022-28094Medium· 6.1
4y ago

SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.

SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.

▾ Sunlitonline_sports_complex_booking_system_project · online_sports_complex_booking_systemEPSS 0.69%via NVD
CVE-2022-26597Medium· 6.1
4y ago

Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via th…

Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via th…

▾ Sunlitliferay · digital_experience_platformEPSS 0.72%via NVD
CVE-2022-26596Medium· 6.1
4y ago

Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 8, allows …

Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 8, allows …

▾ Sunlitliferay · digital_experience_platformEPSS 0.72%via NVD
CVE-2022-29533Medium· 6.1
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situation with a "weird single checkbox page."

▾ Sunlitmisp-project · mispEPSS 0.84%via NVD
CVE-2022-29532Medium· 4.8
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascript: URL in the URL field, and another administrator clicks on it.

▾ Sunlitmisp-project · mispEPSS 0.84%via NVD
CVE-2022-29531Medium· 5.4
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.

▾ Sunlitmisp-project · mispEPSS 0.83%via NVD
CVE-2022-29530Medium· 5.4
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.

▾ Sunlitmisp-project · mispEPSS 0.83%via NVD
CVE-2022-29529Medium· 5.4
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.

▾ Sunlitmisp-project · mispEPSS 0.83%via NVD
CVE-2022-26593Medium· 5.4
4y ago

Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via …

Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via …

▾ Sunlitliferay · digital_experience_platformEPSS 0.58%via NVD
CVE-2022-26594Medium· 6.1
4y ago

Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms …

Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help text to (1) Forms …

▾ Sunlitliferay · liferay_portalEPSS 0.73%via NVD
CVE-2021-43432Medium· 6.1
4y ago

A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.

A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.

▾ Sunlitexrick · xmallEPSS 0.84%via NVD
CWE-79 vulnerabilities (CVEs) — page 66 · VulnSea