Vulnerabilities (CVE)

Filtered by CWE-79
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25375 1 Softrade 1 Wp Smart Crm \& Invoices 2020-09-18 3.5 LOW 5.4 MEDIUM
Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by: Cross Site Scripting via the Business Name field, Tax Code field, First Name field, Address field, Town field, Phone field, Mobile field, Place of Birth field, Web Site field, VAT Number field, Last Name field, Fax field, Email field, and Skype field.
CVE-2020-2271 1 Jenkins 1 Locked Files Report 2020-09-18 3.5 LOW 5.4 MEDIUM
Jenkins Locked Files Report Plugin 1.6 and earlier does not escape locked files' names in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
CVE-2020-5306 1 Codologic 1 Codoforum 2020-09-18 3.5 LOW 4.8 MEDIUM
Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.
CVE-2020-21845 1 Codoforum 1 Codoforum 2020-09-18 4.3 MEDIUM 6.1 MEDIUM
Codoforum 4.8.3 allows HTML Injection in the 'admin dashboard Manage users Section.'
CVE-2020-10227 1 Vtenext 1 Vtenext 2020-09-18 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the messages module of vtecrm vtenext 19 CE allows attackers to inject arbitrary JavaScript code via the From field of an email.
CVE-2020-2265 1 Jenkins 1 Coverage\/complexity Scatter Plot 2020-09-18 3.5 LOW 5.4 MEDIUM
Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not escape the method information in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step.
CVE-2020-21732 1 Rukovoditel 1 Rukovoditel 2020-09-17 4.3 MEDIUM 6.1 MEDIUM
Rukovoditel Project Management app 2.6 is affected by: Cross Site Scripting (XSS). An attacker can add JavaScript code to the filename.
CVE-2020-25378 1 Accesspressthemes 1 Wp Floating Menu 2020-09-17 4.3 MEDIUM 6.1 MEDIUM
Wordpress Plugin Store / AccessPress Themes WP Floating Menu V1.3.0 is affected by: Cross Site Scripting (XSS) via the id GET parameter.
CVE-2020-21733 1 Sagemcom 2 F\@st 3686, F\@st 3686 Firmware 2020-09-17 4.3 MEDIUM 6.1 MEDIUM
Sagemcom F@ST3686 v1.0 HUN 3.97.0 has XSS via RgDiagnostics.asp, RgDdns.asp, RgFirewallEL.asp, RgVpnL2tpPptp.asp.
CVE-2020-9737 1 Adobe 1 Experience Manager 2020-09-17 3.5 LOW 4.8 MEDIUM
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
CVE-2020-21731 1 Gazie Project 1 Gazie 2020-09-17 4.3 MEDIUM 6.1 MEDIUM
Gazie 7.29 is affected by: Cross Site Scripting (XSS) via http://192.168.100.7/gazie/modules/config/admin_utente.php?user_name=amministratore&Update. An attacker can inject JavaScript code, and the webapplication stores the injected code.
CVE-2019-14756 1 Kaiostech 1 Kaios 2020-09-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in KaiOS 1.0, 2.5, and 2.5.12.5. The pre-installed Email application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a specially crafted email to the victim that will inject HTML into the email application's UI as soon as the email is opened. At a bare minimum, this allows an attacker to take control over the Email application's UI (e.g., display a malicious prompt to the user asking them to re-enter their email credentials) and also allows an attacker to abuse any of the privileges available to the mobile application.
CVE-2019-14757 1 Kaiostech 1 Kaios 2020-09-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed Contacts application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a vCard file to the victim that will inject HTML into the Contacts application (assuming the victim chooses to import the file). At a bare minimum, this allows an attacker to take control over the Contacts application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.
CVE-2019-14758 1 Kaiostech 1 Kaios 2020-09-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed File Manager application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a file via email to the victim that will inject HTML into the File Manager application (assuming the victim chooses to download the email attachment). At a bare minimum, this allows an attacker to take control over the File Manager application's UI (e.g., display a malicious prompt to the user asking them to re-enter credentials such as their KaiOS credentials to continue using the application) and also allows an attacker to abuse any of the privileges available to the mobile application.
CVE-2019-15587 1 Loofah Project 1 Loofah 2020-09-17 3.5 LOW 5.4 MEDIUM
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
CVE-2020-13301 1 Gitlab 1 Gitlab 2020-09-16 3.5 LOW 4.8 MEDIUM
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored XSS on the standalone vulnerability page.
CVE-2020-2262 1 Jenkins 1 Android Lint 2020-09-16 3.5 LOW 5.4 MEDIUM
Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to the plugin's post-build step.
CVE-2020-2263 1 Jenkins 1 Radiator View 2020-09-16 3.5 LOW 5.4 MEDIUM
Jenkins Radiator View Plugin 1.29 and earlier does not escape the full name of the jobs in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
CVE-2020-2264 1 Jenkins 1 Custom Job Icon 2020-09-16 3.5 LOW 5.4 MEDIUM
Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
CVE-2020-2257 1 Jenkins 1 Validating String Parameter 2020-09-16 3.5 LOW 5.4 MEDIUM
Jenkins Validating String Parameter Plugin 2.4 and earlier does not escape various user-controlled fields, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
CVE-2020-2266 1 Jenkins 1 Description Column 2020-09-16 3.5 LOW 5.4 MEDIUM
Jenkins Description Column Plugin 1.3 and earlier does not escape the job description in the column tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
CVE-2020-2256 1 Jenkins 1 Pipeline Maven Integration 2020-09-16 3.5 LOW 5.4 MEDIUM
Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
CVE-2020-2259 1 Jenkins 1 Computer Queue 2020-09-16 3.5 LOW 5.4 MEDIUM
Jenkins computer-queue-plugin Plugin 1.5 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
CVE-2020-2269 1 Jenkins 1 Chosen-views-tabbar 2020-09-16 3.5 LOW 5.4 MEDIUM
Jenkins chosen-views-tabbar Plugin 1.2 and earlier does not escape view names in the dropdown to select views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to configure views.
CVE-2020-2270 1 Jenkins 1 Clearcase Release 2020-09-16 3.5 LOW 5.4 MEDIUM
Jenkins ClearCase Release Plugin 0.3 and earlier does not escape the composite baseline in badge tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
CVE-2020-9742 1 Adobe 1 Experience Manager 2020-09-16 3.5 LOW 5.4 MEDIUM
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below) and 6.3.3.8 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Inbox calendar feature. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
CVE-2017-15947 1 Aspsource 1 Simple Asc Content Management System 2020-09-16 3.5 LOW 5.4 MEDIUM
Simple ASC Content Management System v1.2 has XSS in the location field in the sign function, related to guestbook.asp, formgb.asp, and msggb.asp.
CVE-2020-4530 1 Ibm 2 Business Automation Workflow, Business Process Manager 2020-09-16 3.5 LOW 5.4 MEDIUM
IBM Business Automation Workflow C.D.0 and IBM Business Process Manager 8.0, 8.5, and 8.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-ForceID: 182714.
CVE-2020-24198 1 Stock Management System Project 1 Stock Management System 2020-09-15 4.3 MEDIUM 6.1 MEDIUM
A persistent cross-site scripting vulnerability in Sourcecodester Stock Management System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'Brand Name.'
CVE-2020-15788 1 Siemens 1 Polarion Subversion Webclient 2020-09-14 4.3 MEDIUM 6.1 MEDIUM
A vulnerability has been identified in Polarion Subversion Webclient (All versions). The Polarion subversion web application does not filter user input in a way that prevents Cross-Site Scripting. If a user is enticed into passing specially crafted, malicious input to the web client (e.g. by clicking on a malicious URL with embedded JavaScript), then JavaScript code can be returned and may then be executed by the user’s client. Various actions could be triggered by running malicious JavaScript code.
CVE-2020-24194 1 Daily Tracker System Project 1 Daily Tracker System 2020-09-14 4.3 MEDIUM 6.1 MEDIUM
A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.
CVE-2020-9736 1 Adobe 1 Experience Manager 2020-09-14 3.5 LOW 4.8 MEDIUM
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields. These scripts may be executed in a victim’s browser when browsing to the page containing the vulnerable field.
CVE-2020-9738 1 Adobe 1 Experience Manager 2020-09-14 3.5 LOW 4.8 MEDIUM
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields. These scripts may be executed in a victim’s browser when visiting the page containing the vulnerable field.
CVE-2020-9740 1 Adobe 1 Experience Manager 2020-09-14 3.5 LOW 5.4 MEDIUM
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Design Importer. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
CVE-2020-6326 1 Sap 1 Netweaver Knowledge Management 2020-09-14 3.5 LOW 5.4 MEDIUM
SAP NetWeaver (Knowledge Management), version-7.30,7.31,7.40,7.50, allows an authenticated attacker to create malicious links in the UI, when clicked by victim, will execute arbitrary java scripts thus extracting or modifying information otherwise restricted leading to Stored Cross Site Scripting.
CVE-2020-9741 1 Adobe 1 Experience Manager 2020-09-14 3.5 LOW 5.4 MEDIUM
The AEM forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
CVE-2020-9735 1 Adobe 1 Experience Manager 2020-09-14 3.5 LOW 4.8 MEDIUM
AEM versions 6.5.5.0 (and below), 6.4.8.1 (and below), 6.3.3.8 (and below) and 6.2 SP1-CFP20 (and below) are affected by a stored XSS vulnerability that allows users with access to the Content Repository Development Environment to store malicious scripts in certain node fields. These scripts may be executed in a victim’s browser when search queries return the page containing the vulnerable field.
CVE-2020-9734 1 Adobe 1 Experience Manager 2020-09-14 3.5 LOW 5.4 MEDIUM
The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.1 (and below) is affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Forms component. These scripts may be executed in a victim’s browser when they open the page containing the vulnerable field.
CVE-2020-24794 1 Kentico 1 Kentico 2020-09-14 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Kentico before 12.0.75.
CVE-2020-24582 1 Zulipchat 1 Zulip Desktop 2020-09-11 4.3 MEDIUM 6.1 MEDIUM
Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user interface.
CVE-2020-24963 1 Appsbd 1 Best Support System 2020-09-11 3.5 LOW 5.4 MEDIUM
An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.
CVE-2019-11928 1 Whatsapp 1 Whatsapp Desktop 2020-09-11 4.3 MEDIUM 6.1 MEDIUM
An input validation issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed cross-site scripting upon clicking on a link from a specially crafted live location message.
CVE-2020-12058 1 Oscommerce 1 Ce Phoenix 2020-09-11 4.3 MEDIUM 6.1 MEDIUM
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php, catalog/admin/languages.php, catalog/admin/countries.php, catalog/admin/tax_classes.php, catalog/admin/reviews.php, or catalog/admin/zones.php; or the zpage or spage parameter to catalog/admin/geo_zones.php.
CVE-2020-4578 5 Hp, Ibm, Linux and 2 more 8 Hp-ux, Aix, I and 5 more 2020-09-11 3.5 LOW 5.4 MEDIUM
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 184433.
CVE-2020-25104 1 Eramba 1 Eramba 2020-09-10 3.5 LOW 5.4 MEDIUM
eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For example, the filename has a complete XSS payload followed by the .png extension.
CVE-2020-25102 1 Advanced Reports Project 1 Advanced Reports 2020-09-10 4.3 MEDIUM 6.1 MEDIUM
silverstripe-advancedreports (aka the Advanced Reports module for SilverStripe) 1.0 through 2.0 is vulnerable to Cross-Site Scripting (XSS) because it is possible to inject and store malicious JavaScript code. The affects admin/advanced-reports/DataObjectReport/EditForm/field/DataObjectReport/item (aka report preview) when an SVG document is provided in the Description parameter.
CVE-2020-4516 1 Ibm 2 Business Automation Workflow, Business Process Manager 2020-09-10 3.5 LOW 5.4 MEDIUM
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182371.
CVE-2020-4698 1 Ibm 2 Business Automation Workflow, Business Process Manager 2020-09-10 3.5 LOW 5.4 MEDIUM
IBM Business Process Manager 8.5, 8.6 and IBM Business Automation Workflow 18.0, 19.0, and 20.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186841.
CVE-2020-6312 1 Sap 1 Businessobjects Business Intelligence Platform 2020-09-10 3.5 LOW 5.4 MEDIUM
SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), versions - 4.1, 4.2, allows an attacker with a non-administrative user account that can edit certain web page properties, can modify how a browser processes particular page elements, leading to stored Cross Site Scripting. In certain situations, when a user accesses an affected web page element, the attacker will be able to access or modify metadata for which they are not authorized.
CVE-2020-6283 1 Sap 1 Fiori Launchpad 2020-09-10 4.3 MEDIUM 6.1 MEDIUM
SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, resulting in reflected Cross-Site Scripting (XSS) vulnerability. With a successful attack, the attacker can steal authentication information of the user, such as data relating to his or her current session.