Vulnerabilities (CVE)

Filtered by CWE-79
Total 29081 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-12590 1 Asus 2 Rt-n14uhp, Rt-n14uhp Firmware 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
ASUS RT-N14UHP devices before 3.0.0.4.380.8015 have a reflected XSS vulnerability in the "flag" parameter.
CVE-2015-2324 1 10web 1 Photo Gallery 2024-02-04 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the filemanager in the Photo Gallery plugin before 1.2.13 for WordPress allows remote authenticated users with edit permission to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-8728 1 Kontena 1 Kontena 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
server/app/views/static/code.html in Kontena before 1.5.0 allows XSS in "kontena master login --remote" code display, as demonstrated by /code#code= in a URI.
CVE-2018-1384 1 Ibm 4 Business Process Manager, Business Process Manager Enterprise Service Bus, Websphere Enterprise Service Bus and 1 more 2024-02-04 3.5 LOW 5.4 MEDIUM
IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138135.
CVE-2017-9783 1 Projectsend 1 Projectsend 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the Description field in a Site name updated.
CVE-2018-9122 1 Crea8social 1 Crea8social 2024-02-04 3.5 LOW 5.4 MEDIUM
In Crea8social 2018.2, there is Reflected Cross-Site Scripting via the term parameter to the /search URI.
CVE-2018-3735 1 Bracket-template Project 1 Bracket-template 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
CVE-2018-0908 1 Microsoft 1 Identity Manager 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Microsoft Identity Manager 2016 SP1 allows an attacker to gain elevated privileges when it does not properly sanitize a specially crafted attribute value being displayed to a user on an affected MIM 2016 server, aka "Microsoft Identity Manager XSS Elevation of Privilege Vulnerability."
CVE-2018-11627 2 Redhat, Sinatrarb 2 Cloudforms, Sinatra 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
CVE-2018-6940 1 Nat32 1 Nat32 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with CSRF.
CVE-2018-1186 1 Dell 1 Emc Isilon 2024-02-04 3.5 LOW 4.8 MEDIUM
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and version 7.1.1.11 is affected by a cross-site scripting vulnerability in the Cluster description of the OneFS web administration interface. A malicious administrator may potentially inject arbitrary HTML or JavaScript code in the user's browser session in the context of the OneFS website.
CVE-2017-8783 1 Synacor 1 Zimbra Collaboration Suite 2024-02-04 3.5 LOW 5.4 MEDIUM
Synacor Zimbra Collaboration Suite (ZCS) before 8.7.10 has Persistent XSS.
CVE-2018-0557 1 Cybozu 1 Mailwise 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Stored cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary web script or HTML 'E-mail Details Screen' via unspecified vectors.
CVE-2018-1000084 1 Wolfcms 1 Wolf Cms 2024-02-04 3.5 LOW 5.4 MEDIUM
WOlfCMS WolfCMS version version 0.8.3.1 contains a Stored Cross-Site Scripting vulnerability in Layout Name (from Layout tab) that can result in low privilege user can steal the cookie of admin user and compromise the admin account. This attack appear to be exploitable via Need to enter the Javascript code into Layout Name .
CVE-2018-6182 1 Mahara 1 Mahara 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code stripping alone but also clean input on the server / PHP side as one can create own packets of POST data containing bad content with which to hit the server.
CVE-2018-10026 1 Yzmcms 1 Yzmcms 2024-02-04 3.5 LOW 4.8 MEDIUM
The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the valid function in application/wechat/controller/index.class.php.
CVE-2018-8247 1 Microsoft 2 Office Online Server, Office Web Apps 2024-02-04 5.8 MEDIUM 5.4 MEDIUM
An elevation of privilege vulnerability exists when Office Web Apps Server 2013 and Office Online Server fail to properly handle web requests, aka "Microsoft Office Elevation of Privilege Vulnerability." This affects Microsoft Office, Microsoft Office Online Server. This CVE ID is unique from CVE-2018-8245.
CVE-2015-3618 1 Nagios 1 Business Process Intelligence 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving index.php.
CVE-2018-8906 1 Dsmall Project 1 Dsmall 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
dsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishandled at public/index.php/home/memberaddress/edit/address_id/2.html.
CVE-2018-11366 1 Loginizer 1 Loginizer 2024-02-04 4.3 MEDIUM 6.1 MEDIUM
init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandled. This is fixed in 1.4.0.