VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2144 CVEsRSS

CVE-2021-43432Medium· 6.1
4y ago

A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.

A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.

▾ Sunlitexrick · xmallEPSS 0.84%via NVD
CVE-2021-42868Medium· 4.8
4y ago

A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parameter in (1) patient/insert, (2) patient_report, (3) appointment_report, (4) visit_report, and (5) bill_detail_report p…

A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parameter in (1) patient/insert, (2) patient_report, (3) appointment_report, (4) visit_report, and (5) bill_detail_report p…

▾ Sunlitchikitsa · patient_management_softwareEPSS 0.51%via NVD
CVE-2022-26644Medium· 6.1
4y ago

Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via parameters on user profile, system_info and accounts management.

Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via parameters on user profile, system_info and accounts management.

▾ Sunlitoretnom23 · banking_systemEPSS 0.64%via NVD
CVE-2022-26244Medium· 5.4
4y ago

A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "special" field.

A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "special" field.

▾ Sunlithospital's_patient_records_management_system_project · hospital's_patient_records_management_systemEPSS 0.49%via NVD
CVE-2021-40906Medium· 6.1PoC
4y ago

CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone

CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content an…

▾ Twilightcheckmk · checkmkEPSS 0.99%via NVD
CVE-2022-26197Medium· 5.4
4y ago

Joget DX 7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Datalist table.

Joget DX 7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Datalist table.

▾ Sunlitjoget · joget_dxEPSS 0.57%via NVD
CVE-2022-26263Medium· 6.1PoC
4y ago

Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.

Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp.

▾ Twilightyonyou · u8+EPSS 42%via NVD
CVE-2022-25574Medium· 4.8
4y ago

A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file.

A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file.

▾ Sunlitdouco · douphpEPSS 0.43%via NVD
CVE-2022-23350Medium· 5.4
4y ago

BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability.

BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability.

▾ Sunlitbigantsoft · bigant_serverEPSS 0.61%via NVD
CVE-2022-27246Medium· 6.1
4y ago

An issue was discovered in MISP before 2.4.156

An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by default.

▾ Sunlitmisp-project · mispEPSS 0.60%via NVD
CVE-2022-27244Medium· 4.8
4y ago

An issue was discovered in MISP before 2.4.156

An issue was discovered in MISP before 2.4.156. A malicious site administrator could store an XSS payload in the custom auth name. This would be executed each time the administrator modifies a user.

▾ Sunlitmisp-project · mispEPSS 0.48%via NVD
CVE-2020-18325Medium· 6.1PoC
4y ago

Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.

Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.

▾ Twilightintelliants · subrion_cmsEPSS 1.6%via NVD
CVE-2020-18324Medium· 6.1PoC
4y ago

Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.

Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.

▾ Twilightintelliants · subrion_cmsEPSS 2.2%via NVD
CVE-2022-24573Medium· 6.1
4y ago

A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unauthenticated users to get admin access by injecting a malicious script in the User-Agent field.

A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unauthenticated users to get admin access by injecting a malicious script in the User-Agent field.

▾ Sunlitelement-it · http_commanderEPSS 0.62%via NVD
CVE-2021-38269Medium· 5.4
4y ago

Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7.3.6 and 7.4.0, and Liferay DXP 7.1 before fix pack 23, 7.2 before fix pack 13, and 7.3 before fix pack 2 allows remote attackers to injec…

Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7.3.6 and 7.4.0, and Liferay DXP 7.1 before fix pack 23, 7.2 before fix pack 13, and 7.3 before fix pack 2 allows remote attackers to injec…

▾ Sunlitliferay · liferay_portalEPSS 0.58%via NVD
CVE-2021-38267Medium· 5.4
4y ago

Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6, and Liferay DXP 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the _com_…

Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3.6, and Liferay DXP 7.3 before fix pack 2 allows remote attackers to inject arbitrary web script or HTML via the _com_…

▾ Sunlitliferay · digital_experience_platformEPSS 0.58%via NVD
CVE-2021-38265Medium· 5.4
4y ago

Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 allow remote attackers to inject arbitrary web script or HTML when creating a collection page via the _com_liferay_asset_list_web_portlet_…

Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 allow remote attackers to inject arbitrary web script or HTML when creating a collection page via the _com_liferay_asset_list_web_portlet_…

▾ Sunlitliferay · digital_experience_platformEPSS 0.58%via NVD
CVE-2021-38264Medium· 6.1
4y ago

Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter

Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote attackers to inject arbitrary web script or HTML into the management toolbar search via the `keywords` parameter. This…

▾ Sunlitliferay · liferay_portalEPSS 0.73%via NVD
CVE-2021-38263Medium· 6.1
4y ago

Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 20 and 7.2 before fix pack 10 allows remote attackers to inj…

Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 20 and 7.2 before fix pack 10 allows remote attackers to inj…

▾ Sunlitliferay · liferay_portalEPSS 0.88%via NVD
CVE-2022-25020Medium· 5.4PoC
4y ago

A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.

A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.

▾ Twilightpluxml · pluxmlEPSS 1.2%via NVD
CVE-2022-25022Medium· 5.4PoC
4y ago

A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.

A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.

▾ Twilighthtmly · htmlyEPSS 1.1%via NVD
CVE-2021-37504Medium· 6.1
4y ago

A cross-site scripting (XSS) vulnerability in the fileNameStr parameter of jQuery-Upload-File v4.0.11 allows attackers to execute arbitrary web scripts or HTML via a crafted file with a Javascript payload in the file name.

A cross-site scripting (XSS) vulnerability in the fileNameStr parameter of jQuery-Upload-File v4.0.11 allows attackers to execute arbitrary web scripts or HTML via a crafted file with a Javascript payload in the file name.

▾ Sunlithayageek · jquery_upload_fileEPSS 0.87%via NVD
CVE-2021-46355Medium· 5.4
4y ago

OCS Inventory 2.9.1 is affected by Cross Site Scripting (XSS)

OCS Inventory 2.9.1 is affected by Cross Site Scripting (XSS). To exploit the vulnerability, the attacker needs to manipulate the name of some device on your computer, such as a printer, replacing the device name with some malicious code…

▾ Sunlitfactorfx · ocs_inventoryEPSS 0.78%via NVD
CVE-2022-23321Medium· 4.8
4y ago

A persistent cross-site scripting (XSS) vulnerability exists on two input fields within the administrative panel when editing users in the XMPie UStore application on version 12.3.7244.0.

A persistent cross-site scripting (XSS) vulnerability exists on two input fields within the administrative panel when editing users in the XMPie UStore application on version 12.3.7244.0.

▾ Sunlitxerox · xmpie_ustoreEPSS 0.59%via NVD
CVE-2021-41445Medium· 6.1
4y ago

A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to execute code in the device of the victim via sending a specific URL to the unauthenticated …

A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to execute code in the device of the victim via sending a specific URL to the unauthenticated …

▾ Sunlitdlink · dir-x1860_firmwareEPSS 1.9%via NVD
CVE-2021-42639Medium· 6.1
4y ago

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization.

▾ Sunlitprinterlogic · web_stackEPSS 1.2%via NVD
CVE-2021-45416Medium· 6.1PoC
4y ago

Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the modules/Scheduling/Courses.php script.

Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the modules/Scheduling/Courses.php script.

▾ Twilightrosariosis · rosariosisEPSS 2.3%via NVD
CVE-2021-45422Medium· 6.1PoC
4y ago

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process "count" parameter via GET

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process "count" parameter via GET. No authentication is required.

▾ Twilightreprisesoftware · reprise_license_managerEPSS 3.2%via NVD
CVE-2021-43677Medium· 6.1
4y ago

Fluxbb v1.4.12 is affected by a Cross Site Scripting (XSS) vulnerability.

Fluxbb v1.4.12 is affected by a Cross Site Scripting (XSS) vulnerability.

▾ Sunlitfluxbb · fluxbbEPSS 0.62%via NVD
CVE-2020-20426Medium· 6.1
4y ago

S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in /function/booksave.php.

S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in /function/booksave.php.

▾ Sunlits-cms · s-cmsEPSS 0.66%via NVD
CWE-79 vulnerabilities (CVEs) — page 67 · VulnSea