Vulnerabilities (CVE)

Filtered by CWE-79
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-8089 1 Piwigo 1 Piwigo 2020-02-14 3.5 LOW 5.4 MEDIUM
Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page.
CVE-2020-2111 1 Jenkins 1 Subversion 2020-02-14 3.5 LOW 5.4 MEDIUM
Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting in a stored cross-site scripting vulnerability.
CVE-2013-1410 1 Perforce 1 P4web 2020-02-14 4.3 MEDIUM 6.1 MEDIUM
Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities
CVE-2019-19547 1 Symantec 1 Endpoint Detection And Response 2020-02-14 4.3 MEDIUM 6.1 MEDIUM
Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. An XSS vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.
CVE-2020-0693 1 Microsoft 1 Sharepoint Enterprise Server 2020-02-13 3.5 LOW 5.4 MEDIUM
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0694.
CVE-2020-0694 1 Microsoft 1 Sharepoint Enterprise Server 2020-02-13 3.5 LOW 5.4 MEDIUM
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0693.
CVE-2019-1020007 1 Owasp 1 Dependency-track 2020-02-13 3.5 LOW 5.4 MEDIUM
Dependency-Track before 3.5.1 allows XSS.
CVE-2012-6449 1 Cpanel 2 Cpanel, Whm 2020-02-13 3.5 LOW 5.4 MEDIUM
The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.
CVE-2019-1566 1 Paloaltonetworks 1 Pan-os 2020-02-12 4.3 MEDIUM 6.1 MEDIUM
The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an unauthenticated attacker to inject arbitrary JavaScript or HTML.
CVE-2012-4519 1 Zenphoto 1 Zenphoto 2020-02-12 4.3 MEDIUM 6.1 MEDIUM
Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS.
CVE-2012-6720 1 Socialengine 1 Socialengine 2020-02-12 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to music/create, (2) location parameter to events/create, or (3) search parameter to widget/index/content_id/*.
CVE-2014-3827 1 Mybb 1 Mybb 2020-02-12 3.5 LOW 5.4 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the title parameter in the (1) edit or (2) add action in the user-users module or the (3) finduser action or the name parameter in an (4) edit action in the user-user module or the (5) editprofile action to modcp.php.
CVE-2013-1760 1 Thebuggenie 1 The Bug Genie 2020-02-12 4.3 MEDIUM 6.1 MEDIUM
The Bug Genie before 3.2.6 has Multiple XSS and HTML Injection Vulnerabilities
CVE-2020-5317 1 Dell 1 Emc Elastic Cloud Storage 2020-02-12 3.5 LOW 4.8 MEDIUM
Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user could exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.
CVE-2013-5988 1 Semperplugins 1 All In One Seo Pack 2020-02-12 4.3 MEDIUM 6.1 MEDIUM
A Cross-site Scripting (XSS) vulnerability exists in the All in One SEO Pack plugin before 2.0.3.1 for WordPress via the Search parameter.
CVE-2019-15619 1 Nextcloud 3 Deck, Nextcloud Server, Talk 2020-02-12 3.5 LOW 4.8 MEDIUM
Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud Deck 0.6.5 causes an XSS when linking them with each others in a project.
CVE-2019-15614 1 Nextcloud 1 Nextcloud 2020-02-12 3.5 LOW 5.4 MEDIUM
Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.
CVE-2014-9470 1 Fork-cms 1 Fork Cms 2020-02-12 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the loadForm function in Frontend/Modules/Search/Actions/Index.php in Fork CMS before 3.8.4 allows remote attackers to inject arbitrary web script or HTML via the q_widget parameter to en/search.
CVE-2012-2517 1 Prestashop 1 Prestashop 2020-02-12 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web script or HTML via the index of the product[] parameter to ajax.php.
CVE-2012-2452 1 Pragmamx 1 Pragmamx 2020-02-12 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in pragmaMx 1.x before 1.12.2 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to modules.php or (2) img_url to includes/wysiwyg/spaw/editor/plugins/imgpopup/img_popup.php.
CVE-2012-4029 1 Chamilo 1 Chamilo 2020-02-12 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web script or HTML via the category_name parameter in an addsentcategory action.
CVE-2014-3826 1 Mybb 1 Mybb 2020-02-12 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in MyBB before 1.6.13 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in the edit action of the config-profile_fields module.
CVE-2015-1394 1 10web 1 Photo Gallery 2020-02-11 3.5 LOW 5.4 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) sort_by, (2) sort_order, (3) items_view, (4) dir, (5) clipboard_task, (6) clipboard_files, (7) clipboard_src, or (8) clipboard_dest parameters in an addImages action to wp-admin/admin-ajax.php.
CVE-2015-2207 1 Netcracker 1 Resource Management System 2020-02-11 3.5 LOW 5.4 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) ctrl, (2) t90001_0_theform_selection, (3) _scroll, (4) tableName, (5) parent, (6) circuit, (7) return, (8) xname, or (9) mpTransactionId parameter.
CVE-2020-8822 1 Digi 4 Transport Wr21, Transport Wr21 Firmware, Transport Wr44 and 1 more 2020-02-11 3.5 LOW 4.8 MEDIUM
Digi TransPort WR21 5.2.2.3, WR44 5.1.6.4, and WR44v2 5.1.6.9 devices allow stored XSS in the web application.
CVE-2020-8788 1 Synaptivemedical 1 Clearcanvas 2020-02-11 4.3 MEDIUM 6.1 MEDIUM
Synaptive Medical ClearCanvas ImageServer 3.0 Alpha allows XSS (and HTML injection) via the Default.aspx UserName parameter. NOTE: the issues/227 reference does not imply that the affected product can be downloaded from GitHub. It was simply a convenient location for a public bug report.
CVE-2014-6413 1 Watchguard 1 Fireware Xtm 2020-02-11 4.3 MEDIUM 6.1 MEDIUM
A Cross-site Scripting (XSS) vulnerability exists in WatchGuard XTM 11.8.3 via the poll_name parameter in the firewall/policy script.
CVE-2012-6666 1 Vbseo 1 Vbseo 2020-02-11 4.3 MEDIUM 6.1 MEDIUM
vBSeo before 3.6.0PL2 allows XSS via the member.php u parameter.
CVE-2013-1353 1 Orangehrm 1 Orangehrm 2020-02-11 3.5 LOW 5.4 MEDIUM
Orange HRM 2.7.1 allows XSS via the vacancy name.
CVE-2019-19661 1 Maxum 1 Rumpus Ftp 2020-02-11 4.3 MEDIUM 6.1 MEDIUM
A Cookie based reflected XSS exists in the Web File Manager of Rumpus FTP Server 8.2.9.1, related to RumpusLoginUserName and snp.
CVE-2020-8115 1 Revive-adserver 1 Revive Adserver 2020-02-11 4.3 MEDIUM 6.1 MEDIUM
A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi. There are currently no known exploits: the session identifier cannot be accessed as it is stored in an http-only cookie as of v3.2.2. On older versions, however, under specific circumstances, it could be possible to steal the session identifier and gain access to the admin interface. The query string sent to the www/delivery/afr.php script was printed back without proper escaping in a JavaScript context, allowing an attacker to execute arbitrary JS code on the browser of the victim.
CVE-2019-7621 1 Elastic 1 Kibana 2020-02-10 3.5 LOW 5.4 MEDIUM
Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim�s browser.
CVE-2019-7671 1 Primasystems 1 Flexair 2020-02-10 3.5 LOW 5.4 MEDIUM
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site.
CVE-2019-7184 1 Qnap 2 Qts, Video Station 2020-02-10 3.5 LOW 4.8 MEDIUM
This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Video Station to their latest versions.
CVE-2019-7185 1 Qnap 2 Music Station, Qts 2020-02-10 3.5 LOW 4.8 MEDIUM
This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music Station to their latest versions.
CVE-2019-16925 1 Flower Project 1 Flower 2020-02-10 4.3 MEDIUM 6.1 MEDIUM
** DISPUTED ** Flower 0.9.3 has XSS via the name parameter in an @app.task call. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing configuration options. They are internal backend config options and person having rights to change them already has full access.
CVE-2019-16926 1 Flower Project 1 Flower 2020-02-10 4.3 MEDIUM 6.1 MEDIUM
** DISPUTED ** Flower 0.9.3 has XSS via a crafted worker name. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing configuration options. They are internal backend config options and person having rights to change them already has full access.
CVE-2019-1578 1 Paloaltonetworks 1 Minemeld 2020-02-10 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker able to convince an authenticated MineMeld admin to type malicious input in the MineMeld UI could execute arbitrary JavaScript code in the admin’s browser.
CVE-2019-10957 1 Geutebrueck 22 G-cam Ebc-2110, G-cam Ebc-2110 Firmware, G-cam Ebc-2111 and 19 more 2020-02-10 3.5 LOW 4.8 MEDIUM
Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated attacker with access to event configuration to store malicious code on the server, which could later be triggered by a legitimate user resulting in code execution within the user’s browser.
CVE-2018-7827 1 Schneider-electric 118 D6220, D6220 Firmware, D6220l and 115 more 2020-02-10 3.5 LOW 5.4 MEDIUM
A Cross-Site Scripting (XSS) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which a remote attacker can execute arbitrary HTML and script code in a user’s browser session.
CVE-2019-0316 1 Sap 1 Netweaver Process Integration 2020-02-10 3.5 LOW 4.8 MEDIUM
SAP NetWeaver Process Integration, versions: SAP_XIESR: 7.20, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, does not sufficiently validate user-controlled inputs, which allows an attacker possessing admin privileges to read and modify data from the victim’s browser, by injecting malicious scripts in certain servlets, which will be executed when the victim is tricked to click on those malicious links, resulting in reflected Cross Site Scripting vulnerability.
CVE-2016-5819 1 Moxa 10 Oncell G3100v2, Oncell G3100v2 Firmware, Oncell G3111 and 7 more 2020-02-10 4.3 MEDIUM 6.1 MEDIUM
Moxa G3100V2 Series, editions prior to Version 2.8, and OnCell G3111/G3151/G3211/G3251 Series, editions prior to Version 1.7 allows a reflected cross-site scripting attack which may allow an attacker to execute arbitrary script code in the user’s browser within the trust relationship between their browser and the server.
CVE-2013-3636 1 Projectpier 1 Projectpier 2020-02-10 3.5 LOW 5.4 MEDIUM
ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag
CVE-2013-3637 1 Projectpier 1 Projectpier 2020-02-10 3.5 LOW 5.4 MEDIUM
ProjectPier 0.8.8 does not use the Secure flag for cookies
CVE-2013-2008 1 Automattic 1 Wp Super Cache 2020-02-10 4.3 MEDIUM 6.1 MEDIUM
WordPress Super Cache Plugin 1.3 has XSS.
CVE-2020-7108 1 Learndash 1 Learndash 2020-02-10 4.3 MEDIUM 6.1 MEDIUM
The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.
CVE-2013-3067 1 Linksys 2 Wrt310n, Wrt310n Firmware 2020-02-10 3.5 LOW 5.4 MEDIUM
Linksys WRT310Nv2 2.0.0.1 is vulnerable to XSS.
CVE-2011-1084 1 Smoothwall 1 Smoothwall Express 2020-02-10 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Smoothwall Express 3.
CVE-2012-2593 1 Atmail 1 Atmail 2020-02-10 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web script or HTML via the Date field of an email.
CVE-2013-3635 1 Projectpier 1 Projectpier 2020-02-10 3.5 LOW 5.4 MEDIUM
ProjectPier 0.8.8 has stored XSS