Text Exploits

31,341 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-112943 EXPLOITDB text
Vacation Rental 1.8 - Stored Cross-Site Scripting (XSS)
by CraCkEr
EIP-2026-112690 EXPLOITDB text
Time Slot Booking Calendar 1.8 - Stored Cross-Site Scripting (XSS)
by CraCkEr
EIP-2026-111500 EXPLOITDB text
Prestashop 8.0.4 - Cross-Site Scripting (XSS)
by Mirabbas Ağalarov
CVE-2023-36348 EXPLOITDB HIGH text
POS Codekop v2.0 - Authenticated RCE
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.
by yuyudhn
CVSS 8.8
EIP-2026-107543 EXPLOITDB text
GZ Forum Script 1.8 - Stored Cross-Site Scripting (XSS)
by CraCkEr
CVE-2023-28285 EXPLOITDB HIGH text
Microsoft 365 Apps - Use After Free
Microsoft Office Remote Code Execution Vulnerability
by nu11secur1ty
CVSS 7.8
CVE-2023-33137 EXPLOITDB HIGH text
Microsoft Excel - RCE
Microsoft Excel Remote Code Execution Vulnerability
by nu11secur1ty
CVSS 7.8
CVE-2023-53904 EXPLOITDB MEDIUM text
Xenforo 2.2.13 - XSS
Xenforo 2.2.13 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the smilie category title parameter. Attackers can create a smilie category with a malicious script that will execute when the admin panel is loaded, potentially enabling further client-side attacks.
by Furkan Karaarslan
CVSS 4.6
CVE-2023-34834 EXPLOITDB MEDIUM text
MCL-Net <4.3.5.8788 - Info Disclosure
A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attackers to gain sensitive information about the configured databases via the "/file" endpoint.
by Victor A. Morales
CVSS 5.3
EIP-2026-103985 EXPLOITDB text
Microsoft OneNote (Version 2305 Build 16.0.16501.20074) 64-bit - Spoofing
by nu11secur1ty
CVE-2023-37164 EXPLOITDB MEDIUM text VERIFIED
Diafan.cms - XSS
Diafan CMS v6.0 was discovered to contain a reflected cross-site scripting via the cat_id parameter at /shop/?module=shop&action=search.
by tmrswrr
CVSS 6.1
EIP-2026-112642 EXPLOITDB text
The Shop v2.5 - SQL Injection
by Ahmet Ümit BAYRAM
CVE-2023-33580 EXPLOITDB MEDIUM text VERIFIED
Phpgurukul Student Study Center Management System V1.0 - XSS
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" field on Admin Profile page.
by VIVEK CHOUDHARY
CVSS 4.8
EIP-2026-108116 EXPLOITDB text
Jobpilot v2.61 - SQL Injection
by Ahmet Ümit BAYRAM
EIP-2026-107508 EXPLOITDB text
Groomify v1.0 - SQL Injection
by Ahmet Ümit BAYRAM
CVE-2023-23956 EXPLOITDB MEDIUM text
Broadcom Symantec SiteMinder WebAgent - Cross-Site Scripting
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
by Harshit Joshi
CVSS 5.4
CVE-2024-58338 EXPLOITDB CRITICAL text
Ateme Flamingo XL Firmware - OS Command Injection
Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject shell commands and gain full root access to the device by bypassing the restricted login environment.
by LiquidWorm
CVSS 10.0
CVE-2023-53911 EXPLOITDB MEDIUM text
Textpattern CMS 4.8.8 - XSS
Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert JavaScript payloads into the excerpt, which will execute when the article is viewed by other users.
by tmrswrr
CVSS 5.4
CVE-2023-53906 EXPLOITDB MEDIUM text VERIFIED
projectSend r1605 - XSS
projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets section that will execute when other users load the affected page, enabling persistent script injection.
by Mirabbas Ağalarov
CVSS 4.8
CVE-2023-53905 EXPLOITDB HIGH text VERIFIED
ProjectSend r1605 - Code Injection
ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrators export action logs as CSV files.
by Mirabbas Ağalarov
CVSS 8.0
CVE-2023-36217 EXPLOITDB CRITICAL text
Xoops CMS <2.5.10 - XSS
Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function.
by tmrswrr
CVSS 9.0
EIP-2026-110191 EXPLOITDB text VERIFIED
Online Thesis Archiving System v1.0 - Multiple-SQLi
by nu11secur1ty
EIP-2026-109565 EXPLOITDB text
Monstra 3.0.4 - Stored Cross-Site Scripting (XSS)
by tmrswrr
EIP-2026-101157 EXPLOITDB text
Anevia Flamingo XS 3.6.5 - Authenticated Root Remote Code Execution
by LiquidWorm
EIP-2026-101156 EXPLOITDB text
Anevia Flamingo XL 3.6.20 - Authenticated Root Remote Code Execution
by LiquidWorm