Filtered by CWE-79
Filtered by vendor Subscriptions
Total 44922 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-46334 1 Kashipara 1 School Management System 2025-11-19 6.1 Medium
kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword parameters in /adminLogin.php.
CVE-2024-46336 1 Kashipara 1 School Management System 2025-11-19 6.1 Medium
kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php.
CVE-2024-46335 1 Phpgurukul 1 Complaint Management System 2025-11-19 4.6 Medium
PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parameters in between-date-userreport.php.
CVE-2025-34157 1 Coollabs 1 Coolify 2025-11-19 9.0 Critical
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embedded JavaScript. When an administrator attempts to delete the project or its associated resource, the payload executes in the admin’s browser context. This results in full compromise of the Coolify instance, including theft of API tokens, session cookies, and access to WebSocket-based terminal sessions on managed servers.
CVE-2024-45712 1 Solarwinds 1 Serv-u 2025-11-19 2.6 Low
SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low.
CVE-2024-44655 1 Phpgurukul 1 Complaint Management System 2025-11-18 6.1 Medium
PHPGurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) via the search parameter in user-search.php.
CVE-2024-44661 1 Phpgurukul 1 Online Shopping Portal 2025-11-18 5.4 Medium
PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php.
CVE-2020-35752 1 Janobe 1 Baby Care System 2025-11-18 5.4 Medium
Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post title parameter.
CVE-2025-45236 1 Dbsyncer Project 1 Dbsyncer 2025-11-18 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Nickname parameter.
CVE-2025-63713 2 Remyandrade, Sourcecodester 2 Matching Type Test, Matchmaster 2025-11-18 6.1 Medium
Cross-Site Scripting (XSS) vulnerability in SourceCodester "MatchMaster" 1.0 allows remote attackers to inject arbitrary web script or HTML via crafted input in the custom test creation feature. The vulnerability exists because the application fails to properly sanitize user-supplied input in test titles and matching pair items before rendering them in the DOM during test execution.
CVE-2025-12869 1 Aenrich 2 A+hrd, A\+hrd 2025-11-18 4.8 Medium
The a+HRD developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing remote attackers with administrator privileges to inject persistent JavaScript codes that are executed in users' browsers upon page load.
CVE-2022-44759 1 Hcltech 1 Hcl Leap 2025-11-18 4.6 Medium
Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.
CVE-2024-30147 1 Hcltech 1 Hcl Leap 2025-11-18 6.5 Medium
Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications.
CVE-2024-30114 1 Hcltech 1 Hcl Leap 2025-11-18 3.7 Low
Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment.
CVE-2024-30113 1 Hcltech 1 Hcl Leap 2025-11-18 6.3 Medium
Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the HTML widget.
CVE-2023-37534 1 Hcltech 1 Hcl Leap 2025-11-18 7.1 High
Insufficient URI protocol whitelist in HCL Leap allows script injection through query parameters.
CVE-2025-34278 1 Nagios 1 Network Analyzer 2025-11-18 5.4 Medium
Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can supply a malicious payload which is stored by the application and later rendered in the context of other users. When a victim views the affected page the injected script executes in the victim's browser context.
CVE-2023-7323 1 Nagios 1 Log Server 2025-11-18 5.4 Medium
Nagios Log Server versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Create User function. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
CVE-2023-7321 1 Nagios 1 Log Server 2025-11-18 5.4 Medium
Nagios Log Server versions prior to 2.1.14 are vulnerable to cross-site scripting (XSS) via the Snapshots Page. Untrusted log content was not safely encoded for the output context, allowing attacker-controlled data present in logs to execute script in the victim’s browser within the application origin.
CVE-2023-7319 1 Nagios 1 Network Analyzer 2025-11-18 5.4 Medium
Nagios Network Analyzer versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Percentile Calculator menu. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.