Skip to main content

CWE archive

CWE-84 CVEs

Programmatic archive

19 CVEs tagged with CWE-840 Critical, 2 High, 16 Medium, 1 Low, 0 Unrated.

CVE-2026-54443

Published Jul 15, 2026

Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values before rende…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2025-58444

Published Sep 8, 2025

The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector local development tool prio…

CVSS 8.6 · High

CVE-2025-30203

Published Mar 31, 2025

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the content of RSS feeds in the RSS w…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25329

Published Feb 27, 2025

An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user information via supplying a crafted link.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-25334

Published Feb 27, 2025

An issue in Suning Commerce Group Suning EMall iOS 9.5.198 allows attackers to access sensitive user information via supplying a crafted link.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-25331

Published Feb 27, 2025

An issue in Beitatong Technology LianJia iOS 9.83.50 allows attackers to access sensitive user information via supplying a crafted link.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-25330

Published Feb 27, 2025

An issue in Boohee Technology Boohee Health iOS 13.0.13 allows attackers to access sensitive user information via supplying a crafted link.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-25326

Published Feb 27, 2025

An issue in Merchants Union Consumer Finance Company Limited Merchants Union Finance iOS 6.19.0 allows attackers to access sensitive user information via supplying a crafted link.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-25325

Published Feb 27, 2025

An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via supplying a crafted link.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-25324

Published Feb 27, 2025

An issue in Shandong Provincial Big Data Center AiShanDong iOS 5.0.0 allows attackers to access sensitive user information via supplying a crafted link.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-25323

Published Feb 27, 2025

An issue in Qianjin Network Information Technology (Shanghai) Co., Ltd 51Job iOS 14.22.0 allows attackers to access sensitive user information via supplying a crafted link.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-42184

Published Jan 23, 2025

BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme. It could allow a malicious operator to attempt to download files using the file:// URI scheme.

CVSS 2.5 · Low

CVE-2024-45045

Published Aug 29, 2024

Collabora Online is a collaborative online office suite based on LibreOffice technology. In the mobile (Android/iOS) device variants of Collabora Online it was possible to inject…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30959

Published Sep 27, 2023

In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7011

Published Jun 3, 2020

Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Reference UI injects a URL into a resu…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1