Search Results (45829 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-55651 1 Portabilis 1 I-educar 2025-06-17 5.4 Medium
i-Educar is free, fully online school management software. Version 2.9 of the application fails to properly validate and sanitize user supplied input, leading to a stored cross-site scripting vulnerability that resides within the user type (Tipo de Usuário) input field. Through this attacker vector a malicious user might be able to retrieve information belonging to another user, which may lead to sensitive information leakage or other malicious actions. As of time of publication, no patched versions are known to exist.
CVE-2024-35432 1 Zkteco 1 Zkbio Cvsecurity 2025-06-17 6.1 Medium
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Cross Site Scripting (XSS) via an Audio File. An authenticated user can injection malicious JavaScript code to trigger a Cross Site Scripting.
CVE-2024-5475 2 Lepileppanen, Wordpress Plugin 2 Responsive Video Embed, Responsive Video Embed 2025-06-17 5.4 Medium
The Responsive video embed WordPress plugin before 0.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2024-4749 1 Tipsandtricks-hq 1 Wp Emember 2025-06-17 8.3 High
The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
CVE-2023-4826 1 Socialdriver 1 Socialdriver 2025-06-17 6.1 Medium
The SocialDriver WordPress theme before version 2024 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties resulting in a cross-site scripting (XSS) attack.
CVE-2024-50599 1 Synacor 1 Zimbra Collaboration Suite 2025-06-17 6.1 Medium
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from improper handling of user-supplied input, allowing an attacker to inject malicious code that is reflected back in the HTML response.
CVE-2024-0184 1 Nia 1 Rrj Nueva Ecija Engineer Online Portal 2025-06-17 2.4 Low
A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/edit_teacher.php of the component Add Enginer. The manipulation of the argument Firstname/Lastname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249442 is the identifier assigned to this vulnerability.
CVE-2022-40361 1 Elitecms 1 Elite Cms 2025-06-17 6.1 Medium
Cross Site Scripting Vulnerability in Elite CRM v1.2.11 allows attacker to execute arbitrary code via the language parameter to the /ngs/login endpoint.
CVE-2024-0776 1 Pb-cms Project 1 Pb-cms 2025-06-17 3.5 Low
A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms 2.0. Affected by this issue is some unknown functionality of the component Comment Handler. The manipulation with the input <div onmouseenter="alert("xss)"> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251678 is the identifier assigned to this vulnerability.
CVE-2024-23735 1 Savignano 1 S-notify 2025-06-17 6.1 Medium
Cross Site Scripting (XSS) vulnerability in in the S/MIME certificate upload functionality of the User Profile pages in savignano S/Notify before 4.0.0 for Confluence allows attackers to manipulate user data via specially crafted certificate.
CVE-2023-40355 1 Axigen 1 Axigen Mobile Webmail 2025-06-17 5.4 Medium
Cross Site Scripting (XSS) vulnerability in Axigen versions 10.3.3.0 before 10.3.3.59, 10.4.0 before 10.4.19, and 10.5.0 before 10.5.5, allows authenticated attackers to execute arbitrary code and obtain sensitive information via the logic for switching between the Standard and Ajax versions.
CVE-2023-52274 1 Yzmcms 1 Yzmcms 2025-06-17 6.1 Medium
member/index/register.html in YzmCMS 6.5 through 7.0 allows XSS via the Referer HTTP header.
CVE-2023-52068 1 Kodcloud 1 Kodbox 2025-06-17 6.1 Medium
kodbox v1.43 was discovered to contain a cross-site scripting (XSS) vulnerability via the operation and login logs.
CVE-2023-50974 1 Appwrite 1 Command Line Interface 2025-06-17 5.5 Medium
In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.
CVE-2023-50092 1 Apiida 1 Api Gateway Manager 2025-06-17 6.1 Medium
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-49950 1 Logpoint 1 Siem 2025-06-17 5.4 Medium
The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a custom Jinja template in the Alert view. A remote attacker can craft a cross-site scripting (XSS) payload and send it to any system or device that sends logs to the SIEM. If an alert is created, the payload will execute upon the alert data being viewed with that template, which can lead to sensitive data disclosure.
CVE-2023-49101 1 Axigen 1 Axigen Mobile Webmail 2025-06-17 6.1 Medium
WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mishandling of viewing the usage of SSL certificates.
CVE-2023-48974 1 Axigen 1 Axigen Mail Server 2025-06-17 9.6 Critical
Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter.
CVE-2023-41619 1 Emlog 1 Emlog 2025-06-17 6.1 Medium
Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article.php?action=write.
CVE-2023-6161 1 Themeum 1 Wp Crowdfunding 2025-06-17 6.1 Medium
The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin