Vulnerabilities (CVE)

Filtered by CWE-79
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-8480 1 Microsoft 1 Sharepoint Enterprise Server 2016 2019-10-03 3.5 LOW 5.4 MEDIUM
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8488, CVE-2018-8498, CVE-2018-8518.
CVE-2017-17062 1 Open-xchange 1 Open-xchange Appsuite 2019-10-03 4.0 MEDIUM 6.5 MEDIUM
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev19 allows remote authenticated users to save arbitrary user attributes by leveraging improper privilege management.
CVE-2018-0908 1 Microsoft 1 Identity Manager 2019-10-03 4.3 MEDIUM 6.1 MEDIUM
Microsoft Identity Manager 2016 SP1 allows an attacker to gain elevated privileges when it does not properly sanitize a specially crafted attribute value being displayed to a user on an affected MIM 2016 server, aka "Microsoft Identity Manager XSS Elevation of Privilege Vulnerability."
CVE-2017-3300 1 Oracle 1 Peoplesoft Enterprise Peopletools 2019-10-03 5.8 MEDIUM 6.1 MEDIUM
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Multichannel Framework). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS v3.0 Base Score 6.1 (Confidentiality and Integrity impacts).
CVE-2015-9420 1 Mightymess 1 Soundcloud Is Gold 2019-10-02 4.3 MEDIUM 6.1 MEDIUM
The soundcloud-is-gold plugin before 2.3.2 for WordPress has XSS via the wp-admin/admin-ajax.php?action=get_soundcloud_player id parameter.
CVE-2019-11741 1 Mozilla 1 Firefox 2019-10-02 4.3 MEDIUM 6.1 MEDIUM
A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any site it can cause to be loaded in the same process. Because addons.mozilla.org and accounts.firefox.com have close ties to the Firefox product, malicious manipulation of these sites within the browser can potentially be used to modify a user's Firefox configuration. These two sites will now be isolated into their own process and not allowed to be loaded in a standard content process. This vulnerability affects Firefox < 69.
CVE-2019-15810 1 Netdisco 1 Netdisco 2019-10-02 4.3 MEDIUM 6.1 MEDIUM
Insufficient sanitization during device search in Netdisco 2.042010 allows for reflected XSS via manipulation of a URL parameter.
CVE-2019-14752 1 Salesagility 1 Suitecrm 2019-10-02 4.3 MEDIUM 6.1 MEDIUM
SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS.
CVE-2019-14952 1 Jetbrains 1 Youtrack 2019-10-02 4.3 MEDIUM 6.1 MEDIUM
JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles.
CVE-2019-14953 2 Jetbrains, Mozilla 2 Youtrack, Firefox 2019-10-02 4.3 MEDIUM 6.1 MEDIUM
JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.
CVE-2019-14961 1 Jetbrains 1 Upsource 2019-10-02 4.3 MEDIUM 6.1 MEDIUM
JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.
CVE-2015-9411 1 Gopostmatic 1 Replyable 2019-10-02 4.3 MEDIUM 6.1 MEDIUM
The Postmatic plugin before 1.4.6 for WordPress has XSS.
CVE-2019-12562 1 Dnnsoftware 1 Dotnetnuke 2019-10-01 4.3 MEDIUM 6.1 MEDIUM
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting.
CVE-2019-16685 1 Dolibarr 1 Dolibarr 2019-10-01 3.5 LOW 5.4 MEDIUM
Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.
CVE-2019-16524 1 Status301 1 Easy Fancybox 2019-10-01 3.5 LOW 4.8 MEDIUM
The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter.
CVE-2015-5008 1 Ibm 1 Websphere Commerce 2019-09-30 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through FP11, 6.0 Feature Pack 4, 7.0 through FP9, 7.0 Feature Pack 5 through 8, and 8.0 before 8.0.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVE-2015-5009 1 Ibm 1 Websphere Commerce 2019-09-30 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through FP11, 6.0 Feature Pack 4, 7.0 through FP9, 7.0 Feature Pack 5 through 8, and 8.0 before 8.0.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVE-2016-2862 1 Ibm 1 Websphere Commerce 2019-09-30 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 before 7.0.0.9 cumulative iFix 3, and 8.0 before 8.0.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVE-2016-3015 1 Ibm 1 Cognos Analytics 2019-09-30 3.5 LOW 5.4 MEDIUM
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887.
CVE-2016-0217 1 Ibm 1 Cognos Analytics 2019-09-30 3.5 LOW 5.4 MEDIUM
IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVE-2016-3031 1 Ibm 1 Cognos Analytics 2019-09-30 3.5 LOW 5.4 MEDIUM
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887.
CVE-2019-4139 1 Ibm 1 Cognos Analytics 2019-09-30 3.5 LOW 5.4 MEDIUM
IBM Cognos Analytics 11.0, 11.1.0, and 11.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158335.
CVE-2019-16686 1 Dolibarr 1 Dolibarr 2019-09-30 3.5 LOW 5.4 MEDIUM
Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin.
CVE-2019-16687 1 Dolibarr 1 Dolibarr 2019-09-30 3.5 LOW 5.4 MEDIUM
Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.
CVE-2019-16688 1 Dolibarr 1 Dolibarr 2019-09-30 3.5 LOW 5.4 MEDIUM
Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)
CVE-2019-16923 1 Kkcms Project 1 Kkcms 2019-09-27 4.3 MEDIUM 6.1 MEDIUM
kkcms 1.3 has jx.php?url= XSS.
CVE-2019-16914 1 Netgate 1 Pfsense 2019-09-27 4.3 MEDIUM 6.1 MEDIUM
An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization.
CVE-2017-5942 1 Wp Mail Project 1 Wp Mail 2019-09-27 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in the WP Mail plugin before 1.2 for WordPress. The replyto parameter when composing a mail allows for a reflected XSS. This would allow you to execute JavaScript in the context of the user receiving the mail.
CVE-2019-16904 1 Teampass 1 Teampass 2019-09-27 3.5 LOW 5.4 MEDIUM
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the change history of the item or tapping on the item.)
CVE-2019-7608 1 Elastic 1 Kibana 2019-09-27 4.3 MEDIUM 6.1 MEDIUM
Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
CVE-2018-17790 1 Prospecta 1 Master Data Online 2019-09-26 4.3 MEDIUM 6.1 MEDIUM
Prospecta Master Data Online (MDO) 2.0 has Stored XSS.
CVE-2015-9444 1 Altosresearch 1 Altos-connect 2019-09-26 4.3 MEDIUM 6.1 MEDIUM
The altos-connect plugin 1.3.0 for WordPress has XSS via the wp-content/plugins/altos-connect/jquery-validate/demo/demo/captcha/index.php/ PATH_SELF.
CVE-2015-9416 1 Onthegosystems 1 Sitepress-multilingual-cms 2019-09-26 4.3 MEDIUM 6.1 MEDIUM
The sitepress-multilingual-cms (WPML) plugin 2.9.3 to 3.2.6 for WordPress has XSS via the Accept-Language HTTP header.
CVE-2019-11464 1 Couchbase 1 Couchbase Server 2019-09-26 4.3 MEDIUM 6.1 MEDIUM
Some enterprises require that REST API endpoints include security-related headers in REST responses. Headers such as X-Frame-Options and X-Content-Type-Options are generally advisable, however some information security professionals additionally look for X-Permitted-Cross-Domain-Policies and X-XSS-Protection, which are more generally applicable to HTML endpoint, to be included too. These headers were not included in Couchbase Server 5.5.0 and 5.1.2 . They are now included in version 6.0.2 in responses from the Couchbase Server Views REST API (port 8092).
CVE-2018-17218 1 Ptc 1 Thingworx Platform 2019-09-26 3.5 LOW 5.4 MEDIUM
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is reflected XSS in the SQUEAL search function.
CVE-2019-14272 1 Silverstripe 1 Silverstripe 2019-09-26 3.5 LOW 5.4 MEDIUM
In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS.
CVE-2015-9423 1 Simplysymphony 1 Plugnedit 2019-09-26 3.5 LOW 5.4 MEDIUM
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load PlugneditBGColor, PlugneditEditorMargin, plugnedit_width, pnemedcount, or plugneditcontent parameters.
CVE-2017-16792 1 Geminabox Project 1 Geminabox 2019-09-26 4.3 MEDIUM 6.1 MEDIUM
Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb.
CVE-2015-9426 1 Manual Image Crop Project 1 Manual Image Crop 2019-09-26 3.5 LOW 4.6 MEDIUM
The manual-image-crop plugin before 1.11 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=mic_editor_window postId parameter.
CVE-2015-9439 1 Addthis 1 Addthis 2019-09-26 3.5 LOW 4.8 MEDIUM
The addthis plugin before 5.0.13 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=addthis_social_widget pubid parameter.
CVE-2015-9436 1 Qurl 1 Dynamic Widgets 2019-09-26 3.5 LOW 5.4 MEDIUM
The dynamic-widgets plugin before 1.5.11 for WordPress has XSS via the wp-admin/admin-ajax.php?action=term_tree prefix or widget_id parameter.
CVE-2015-9438 1 Display-widgets Project 1 Display-widgets 2019-09-26 3.5 LOW 5.4 MEDIUM
The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_base, widget_number, or instance parameter.
CVE-2015-9430 1 Crazy Bone Project 1 Crazy Bone 2019-09-26 4.3 MEDIUM 6.1 MEDIUM
The crazy-bone plugin before 0.6.0 for WordPress has XSS via the User-Agent HTTP header.
CVE-2019-12205 1 Silverstripe 1 Silverstripe 2019-09-26 4.3 MEDIUM 6.1 MEDIUM
SilverStripe through 4.3.3 has Flash Clipboard Reflected XSS.
CVE-2015-9414 1 Wpsymposiumpro 1 Wp-symposium 2019-09-26 4.3 MEDIUM 6.1 MEDIUM
The wp-symposium plugin through 15.8.1 for WordPress has XSS via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter.
CVE-2015-9419 1 Captain-slider Project 1 Captain-slider 2019-09-26 4.3 MEDIUM 6.1 MEDIUM
The captain-slider plugin 1.0.6 for WordPress has XSS via a Title or Caption section.
CVE-2015-9412 1 Royal-slider Project 1 Royal-slider 2019-09-26 4.3 MEDIUM 6.1 MEDIUM
The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter.
CVE-2019-15120 1 Kunena 1 Kunena 2019-09-26 4.3 MEDIUM 6.1 MEDIUM
The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
CVE-2019-16890 1 Halo 1 Halo 2019-09-26 3.5 LOW 5.4 MEDIUM
Halo 1.1.0 has XSS via a crafted authorUrl in JSON data to api/content/posts/comments.
CVE-2019-10406 1 Jenkins 1 Jenkins 2019-09-25 3.5 LOW 4.8 MEDIUM
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not restrict or filter values set as Jenkins URL in the global configuration, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission.