5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-45313
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in the /tasks endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the title parameter.

CVE-2025-63640
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 2 PoCs

Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Medicine Name" and "Notes (Optional)" fields when creating an "Upcoming Reminder", allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the victim's browser upon clicking the "Save Reminder" button.

CVE-2025-3191
react-draft-wysiwyg Web
6.1
MEDIUM
EPSS
0.2%
2025 CWE-79 1 PoC

All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the <iframe> tag.

CVE-2025-55035
Mattermost General
6.1
MEDIUM
EPSS
0.0%
2025 CWE-754 1 PoC

Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the Desktop App via having the user configure the malicious server and forcing a modal popup that cannot be closed.

CVE-2025-29410
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in the component /contact.php of Hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the txtEmail parameter.

CVE-2025-65289
Software Genérico Web Networking
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A stored Cross site scripting (XSS) vulnerability in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) router allows a remote attacker on the LAN to inject JavaScript into the router's management UI by submitting a malicious hostname. The injected script is stored and later executed in the context of an administrator's browser (for example after DHCP release/renew triggers the interface to display the stored hostname). Because the management interface uses weak/basic authentication and does not properly protect or isolate session material, the XSS can be used to exfiltrate the admin

CVE-2025-61255
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Bank Locker Management System by PHPGurukul is affected by a Cross-Site Scripting (XSS) vulnerability via the /search parameter, where unsanitized input allows arbitrary HTML and JavaScript injection, potentially resulting in information disclosure and user redirection.

CVE-2025-66906
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Cross Site Request Forgery (CSRF) vulnerability in Turms Admin API thru v0.10.0-SNAPSHOT allows attackers to gain escalated privileges.

CVE-2025-9862
Ghost General
6.1
MEDIUM
EPSS
0.0%
2025 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue affects Ghost: from 6.0.0 through 6.0.8, from 5.99.0 through 5.130.3.

CVE-2025-45083
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect access control in Ullu (Android version v2.9.929 and IOS version v2.8.0) allows attackers to bypass parental pin feature via unspecified vectors.

CVE-2025-60318
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the fname (First Name) and lname (Last Name) fields.

CVE-2025-67833
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the tag parameter.

CVE-2025-65790
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

A reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file manager interface. FuguHub does not sanitize or restrict script execution inside SVG content. When a victim opens a crafted SVG containing an inline <script> element, the browser executes the attacker-controlled JavaScript.

CVE-2025-14284
@tiptap/extension-link Web
6.1
MEDIUM
EPSS
0.0%
2025 CWE-79 1 PoC

Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanitized user input allowed in setting or toggling links. An attacker can execute arbitrary JavaScript code in the context of the application by injecting a javascript: URL payload into these attributes, which is then triggered either by user interaction.

CVE-2025-9034
Wp Edit Password Protected Web Windows
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

CVE-2025-60453
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the column management module, specifically in the app\system\column\admin\index.class.php component. The vulnerability allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed by users.

CVE-2025-46611
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

Cross Site Scripting vulnerability in ARTEC EMA Mail v6.92 allows an attacker to execute arbitrary code via a crafted script.

CVE-2025-56526
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Cross site scripting (XSS) vulnerability in Kotaemon 0.11.0 allowing attackers to execute arbitrary code via a crafted PDF.

CVE-2025-26258
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 2 PoCs

Sourcecodester Employee Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via 'Add Designation.'

CVE-2025-45316
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

A cross-site scripting (XSS) vulnerability in the TextBlockModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter.