Filtered by CWE-79
Filtered by vendor Subscriptions
Total 44986 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-24803 1 Opensecurity 1 Mobile Security Framework 2025-07-07 5.4 Medium
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanumeric characters (A–Z, a–z, and 0–9), hyphens (-), and periods (.). However, an attacker can manually modify this value in the `Info.plist` file and add special characters to the `<key>CFBundleIdentifier</key>` value. The `dynamic_analysis.html` file does not sanitize the received bundle value from Corellium and as a result, it is possible to break the HTML context and achieve Stored XSS. This issue has been addressed in version 4.3.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2025-6613 2 Anujk305, Phpgurukul 2 Hospital Management System, Hospital Management System 2025-07-07 3.5 Low
A vulnerability classified as problematic was found in PHPGurukul Hospital Management System 4.0. Affected by this vulnerability is an unknown functionality of the file /doctor/manage-patient.php. The manipulation of the argument Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2018-13065 1 Owasp 1 Modsecurity 2025-07-03 N/A
ModSecurity 3.0.0 has XSS via an onerror attribute of an IMG element. NOTE: a third party has disputed this issue because it may only apply to environments without a Core Rule Set configured
CVE-2024-35545 1 Mapos 1 Map-os 2025-07-03 6.1 Medium
MAP-OS v4.45.0 and earlier was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2024-36819 1 Mapos 1 Map-os 2025-07-03 5.4 Medium
MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to insert a malicious payload into the "Client Name" input. When a service order from this client is created, the malicious payload is displayed on the administrator and employee dashboards, resulting in unauthorized script execution whenever the dashboard is loaded.
CVE-2024-3754 1 Mnbaa 1 Alemha Watermark 2025-07-03 4.7 Medium
The Alemha watermarker WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2024-33210 1 Flatpress 1 Flatpress 2025-07-03 5.4 Medium
A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users.
CVE-2024-45960 1 Tribalsystems 1 Zenario 2025-07-03 4.8 Medium
Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the website, it can trigger a Cross Site Scripting (XSS) attack.
CVE-2024-45964 1 Tribalsystems 1 Zenario 2025-07-03 4.8 Medium
Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field.
CVE-2024-46409 1 Seeddms 1 Seeddms 2025-07-03 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter in the Calendar page.
CVE-2024-42901 1 Limesurvey 1 Limesurvey 2025-07-03 4.8 Medium
A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted CSV file.
CVE-2024-44085 1 Onlyoffice 2 Docs, Onlyoffice 2025-07-03 6.1 Medium
ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoked function expression (IIFE) for a macro. NOTE: this issue exists because of an incorrect fix for CVE-2021-43446 and CVE-2023-50883.
CVE-2024-57599 1 Douco 1 Douphp 2025-07-03 4.8 Medium
Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in /admin/article.php
CVE-2024-33297 1 Microweber 1 Microweber 2025-07-03 4.7 Medium
Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function
CVE-2024-33298 1 Microweber 1 Microweber 2025-07-03 6.1 Medium
Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup
CVE-2024-33299 1 Microweber 1 Microweber 2025-07-03 4.7 Medium
Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users
CVE-2024-53620 1 Spip 1 Spip 2025-07-03 4.8 Medium
A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.
CVE-2024-55239 1 Portabilis 1 I-educar 2025-07-03 5.4 Medium
A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows attacker to craft malicious urls with arbitrary javascript in the 'titulo_documento' parameter.
CVE-2025-4955 1 Amauri 1 Tarteaucitron.io 2025-07-02 4.7 Medium
The tarteaucitron.io WordPress plugin before 1.9.5 uses query parameters from YouTube oEmbed URLs without sanitizing these parameters correctly, which could allow users with the contributor role and above to perform Stored Cross-site Scripting attacks.
CVE-2025-45661 1 Heavenspell 1 Minitcg 2025-07-02 5.9 Medium
A cross-site scripting (XSS) vulnerability in miniTCG v1.3.1 beta allows attackers to execute abritrary web scripts or HTML via injecting a crafted payload into the id parameter at /members/edit.php.