Vulnerabilities (CVE)

Filtered by CWE-79
Total 30552 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-41371 1 Organizr 1 Organizr 2024-09-04 N/A 6.1 MEDIUM
Organizr v1.90 is vulnerable to Cross Site Scripting (XSS) via api.php.
CVE-2024-41358 1 Phpipam 1 Phpipam 2024-09-04 N/A 6.1 MEDIUM
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.
CVE-2024-41351 1 Baijunyao 1 Bjyadmin 2024-09-04 N/A 6.1 MEDIUM
bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/getContent.php
CVE-2024-41350 1 Baijunyao 1 Bjyadmin 2024-09-04 N/A 6.1 MEDIUM
bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/imageUp.php
CVE-2024-41348 1 Jpatokal 1 Openflights 2024-09-04 N/A 6.1 MEDIUM
openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/alsearch.php
CVE-2024-41347 1 Jpatokal 1 Openflights 2024-09-04 N/A 6.1 MEDIUM
openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/settings.php
CVE-2024-41346 1 Jpatokal 1 Openflights 2024-09-04 N/A 5.4 MEDIUM
openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/submit.php
CVE-2024-44920 1 Seacms 1 Seacms 2024-09-04 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the siteurl parameter.
CVE-2024-8004 1 3ds 1 3dexperience Enovia 2024-09-04 N/A 5.4 MEDIUM
A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
CVE-2024-7938 1 3ds 1 3dexperience 2024-09-04 N/A 5.4 MEDIUM
A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.
CVE-2024-38858 1 Checkmk 1 Checkmk 2024-09-04 N/A 6.1 MEDIUM
Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.
CVE-2024-5024 1 Memberpress 1 Memberpress 2024-09-04 N/A 6.1 MEDIUM
The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mepr_screenname' and 'mepr_key' parameter in all versions up to, and including, 1.11.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVE-2024-4401 1 Wpvibes 1 Elementor Addon Elements 2024-09-04 N/A 5.4 MEDIUM
The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ and 'eae_slider_animation' parameters in all versions up to, and including, 1.13.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-41345 1 Jpatokal 1 Openflights 2024-09-04 N/A 5.4 MEDIUM
openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/trip.php
CVE-2024-43921 1 Magic-post-thumbnail 1 Magic Post Thumbnail 2024-09-04 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Magic Post Thumbnail allows Reflected XSS.This issue affects Magic Post Thumbnail: from n/a through 5.2.9.
CVE-2024-43920 1 Jegstudio 1 Gutenverse 2024-09-04 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jegstudio Gutenverse allows Stored XSS.This issue affects Gutenverse: from n/a through 1.9.4.
CVE-2024-8366 1 Code-projects 1 Pharmacy Management System 2024-09-04 5.0 MEDIUM 4.7 MEDIUM
A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?id=userProfileEdit of the component Update My Profile Page. The manipulation of the argument fname/lname/email with the input <script>alert(1)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-5212 1 Tagdiv 1 Tagdiv Composer 2024-09-03 N/A 6.1 MEDIUM
The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and including, 5.0 due to insufficient input sanitization and output escaping within the on_ajax_register_forum_user function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVE-2024-7942 1 Rems 1 Leads Manager Tool 2024-09-03 4.0 MEDIUM 5.4 MEDIUM
A vulnerability has been found in SourceCodester Leads Manager Tool 1.0 and classified as problematic. This vulnerability affects unknown code of the file update-leads.php. The manipulation of the argument phone_number leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-42901 2024-09-03 N/A 4.8 MEDIUM
A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted CSV file.