Filtered by CWE-79
Total 35509 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-3825 1 Senior-walter 1 Web-based Pharmacy Product Management System 2025-04-30 2.4 Low
A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this issue is some unknown functionality of the file add-category.php. The manipulation of the argument txtcategory_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-3826 1 Senior-walter 1 Web-based Pharmacy Product Management System 2025-04-30 2.4 Low
A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part of the file add-supplier.php. The manipulation of the argument txtsupplier_name/txtaddress leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-52459 2025-04-30 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chameleoni.Com Chameleoni Jobs chameleon-jobs allows Reflected XSS.This issue affects Chameleoni Jobs: from n/a through 2.5.4.
CVE-2022-30768 1 Zoneminder 1 Zoneminder 2025-04-30 5.4 Medium
A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.
CVE-2025-25001 2025-04-30 4.3 Medium
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2024-26473 1 Msaad1999 1 Klik Socialmediawebsite 2025-04-30 6.1 Medium
A reflected cross-site scripting (XSS) vulnerability in SocialMediaWebsite v1.0.1 allows attackers to inject malicious JavaScript into the web browser of a victim via the poll parameter in poll.php.
CVE-2024-26472 1 Msaad1999 1 Klik Socialmediawebsite 2025-04-30 6.1 Medium
KLiK SocialMediaWebsite version 1.0.1 from msaad1999 has a reflected cross-site scripting (XSS) vulnerability which may allow remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' or 'validator' parameters of 'create-new-pwd.php'.
CVE-2024-26471 1 Msaad1999 1 Klik Socialmediawebsite 2025-04-30 5.4 Medium
A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaScript into the web browser of a victim via the search parameter in offer.php.
CVE-2024-42769 2 Jayesh, Kashipara 2 Hotel Management System, Hotel Management System 2025-04-30 6.1 Medium
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "user_fname" and "user_lname" parameters.
CVE-2024-42770 2 Jayesh, Kashipara 2 Hotel Management System, Hotel Management 2025-04-30 4.7 Medium
A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via the "user_email" parameter.
CVE-2024-42771 2 Jayesh, Kashipara 2 Hotel Management System, Hotel Management System 2025-04-30 4.8 Medium
A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "room_name" parameter.
CVE-2025-43954 1 Quasar 1 Qmarkdown 2025-04-30 4.9 Medium
QMarkdown (aka quasar-ui-qmarkdown) before 2.0.5 allows XSS via headers even when when no-html is set.
CVE-2024-29644 1 Dcatadmin 1 Dcat Admin 2025-04-30 6.1 Medium
Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code via a crafted script to the user login box.
CVE-2024-32391 1 Maccms 1 Maccms 2025-04-30 7.3 High
Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.
CVE-2024-30890 1 Ed01-cms Project 1 Ed01-cms 2025-04-30 4.7 Medium
Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categories.php component.
CVE-2024-31574 1 Twcms 1 Twcms 2025-04-30 5 Medium
Cross Site Scripting vulnerability in TWCMS v.2.6 allows a local attacker to execute arbitrary code via a crafted script
CVE-2024-37764 1 Machform 1 Machform 2025-04-30 5.4 Medium
MachForm up to version 19 is affected by an authenticated stored cross-site scripting.
CVE-2024-37763 1 Machform 1 Machform 2025-04-30 5.4 Medium
MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.
CVE-2025-46228 1 Avecnous 1 Event Post 2025-04-30 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post allows DOM-Based XSS. This issue affects Event post: from n/a through 5.9.11.
CVE-2025-46229 1 Textmetrics 1 Textmetrics 2025-04-30 5.9 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Israpil Textmetrics allows Stored XSS. This issue affects Textmetrics: from n/a through 3.6.2.