Vulnerabilities (CVE)

Filtered by CWE-79
Total 29268 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-0499 2 Canonical, Xapian 2 Ubuntu Linux, Xapian-core 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().
CVE-2015-4557 1 Nextendweb 1 Nextend Twitter Connect 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the new_Twitter_sign_button function in nextend-Twitter-connect.php in the Nextend Twitter Connect plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter. NOTE: this may overlap CVE-2015-4413.
CVE-2018-11403 1 Domainmod 1 Domainmod 2024-02-04 3.5 LOW 5.4 MEDIUM
DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.
CVE-2017-5536 1 Tibco 1 Datasynapse Gridserver Manager 2024-02-04 3.5 LOW 5.4 MEDIUM
The GridServer Broker, and GridServer Director components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities which may allow an authenticated user to perform cross-site scripting (XSS). In addition, an authenticated user could be a victim of a cross-site request forgery (CSRF) attack. Affected releases include TIBCO Software Inc.'s TIBCO DataSynapse GridServer Manager: versions up to and including 5.1.3; 6.0.0; 6.0.1; 6.0.2; 6.1.0; 6.1.1; and 6.2.0.
CVE-2018-1413 2 Ibm, Netapp 2 Cognos Analytics, Oncommand Insight 2024-02-04 3.5 LOW 5.4 MEDIUM
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138819.
CVE-2018-13865 1 Idreamsoft 1 Icms 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in idreamsoft iCMS 7.0.9. XSS exists via the callback parameter in a public/api.php uploadpic request, bypassing the iWAF protection mechanism.
CVE-2018-0200 1 Cisco 1 Prime Service Catalog 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
A vulnerability in the web-based interface of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based interface of an affected product. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvh65713.
CVE-2018-7196 1 Osticket 1 Osticket 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" parameter.
CVE-2018-0327 1 Cisco 2 Identity Services Engine, Identity Services Engine Software 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
A vulnerability in the web framework of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected software via the HTTP GET and HTTP POST methods. An attacker who can convince a user to follow an attacker-supplied link could execute arbitrary script or HTML code in the user's browser in the context of an affected site. Cisco Bug IDs: CSCvg86743.
CVE-2018-6891 1 Ladela 1 Bookly 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js.
CVE-2018-9864 1 3cx 1 Live Chat 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.
CVE-2018-11512 1 Creatiwity 1 Witycms 2024-02-04 3.5 LOW 4.8 MEDIUM
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to admin/settings/general.
CVE-2017-1281 1 Ibm 2 Rational Collaborative Lifecycle Management, Rational Quality Manager 2024-02-04 3.5 LOW 5.4 MEDIUM
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124759.
CVE-2018-10367 1 Wuzhicms 1 Wuzhi Cms 2024-02-04 3.5 LOW 4.8 MEDIUM
An issue was discovered in WUZHI CMS 4.1.0. The content-management feature has Stored XSS via the title or content section.
CVE-2017-1621 1 Ibm 2 Rational Collaborative Lifecycle Management, Rational Quality Manager 2024-02-04 3.5 LOW 5.4 MEDIUM
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133088.
CVE-2017-17703 1 Synacor 1 Zimbra Collaboration Suite 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Synacor Zimbra Collaboration Suite (ZCS) before 8.8.3 has Persistent XSS.
CVE-2017-7799 1 Mozilla 1 Firefox 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML". Data on this page is supplied by WebRTC usage and is not under third-party control, making this difficult to exploit, but the vulnerability could possibly be used for a cross-site scripting (XSS) attack. This vulnerability affects Firefox < 55.
CVE-2017-8993 1 Microfocus 1 Project And Portfolio Management 2024-02-04 3.5 LOW 5.4 MEDIUM
A Remote Cross-Site Scripting vulnerability in HPE Project and Portfolio Management (PPM) version v9.30, v9.31, v9.32, v9.40 was found.
CVE-2018-12432 1 Javamelody Project 1 Javamelody 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.
CVE-2018-0551 1 Cybozu 1 Garoon 2024-02-04 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.1 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.