Search
Total
13741 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2019-6599 | 1 F5 | 1 Big-ip Access Policy Manager | 2019-03-18 | 4.3 MEDIUM | 6.1 MEDIUM |
| In BIG-IP 11.6.1-11.6.3.2 or 11.5.1-11.5.8, or Enterprise Manager 3.1.1, improper escaping of values in an undisclosed page of the configuration utility may result with an improper handling on the JSON response when it is injected by a malicious script via a remote cross-site scripting (XSS) attack. | |||||
| CVE-2018-20322 | 1 Limesurvey | 1 Limesurvey | 2019-03-18 | 4.3 MEDIUM | 6.1 MEDIUM |
| LimeSurvey version 3.15.5 contains a Cross-site scripting (XSS) vulnerability in Survey Resource zip upload, resulting in Javascript code execution against LimeSurvey administrators. Fixed in version 3.15.6. | |||||
| CVE-2018-12100 | 1 Sonatype | 1 Nexus Repository Manager | 2019-03-18 | 3.5 LOW | 4.8 MEDIUM |
| Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI. | |||||
| CVE-2014-10078 | 1 Vembu | 1 Storegrid | 2019-03-18 | 4.3 MEDIUM | 6.1 MEDIUM |
| Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registercustomer/onlineregfailure.php. | |||||
| CVE-2018-20418 | 1 Craftcms | 1 Craft Cms | 2019-03-16 | 3.5 LOW | 4.8 MEDIUM |
| index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab. | |||||
| CVE-2017-5877 | 1 Dotcms | 1 Dotcms | 2019-03-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter. | |||||
| CVE-2017-5876 | 1 Dotcms | 1 Dotcms | 2019-03-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter. | |||||
| CVE-2017-5875 | 1 Dotcms | 1 Dotcms | 2019-03-15 | 3.5 LOW | 5.4 MEDIUM |
| XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter. | |||||
| CVE-2018-19391 | 1 Cobham | 4 Satcom Sailor 250, Satcom Sailor 250 Firmware, Satcom Sailor 500 and 1 more | 2019-03-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cobham Satcom Sailor 250 and 500 devices before 1.25 contained persistent XSS, which could be exploited by an unauthenticated threat actor via the /index.lua?pageID=Phone%20book name field. | |||||
| CVE-2018-19394 | 1 Cobham | 4 Satcom Sailor 800, Satcom Sailor 800 Firmware, Satcom Sailor 900 and 1 more | 2019-03-15 | 3.5 LOW | 4.8 MEDIUM |
| Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file. | |||||
| CVE-2019-9711 | 1 Joomla | 1 Joomla\! | 2019-03-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in Joomla! before 3.9.4. The item_title layout in edit views lacks escaping, leading to XSS. | |||||
| CVE-2019-9712 | 1 Joomla | 1 Joomla\! | 2019-03-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in Joomla! before 3.9.4. The JSON handler in com_config lacks input validation, leading to XSS. | |||||
| CVE-2019-9714 | 1 Joomla | 1 Joomla\! | 2019-03-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in Joomla! before 3.9.4. The media form field lacks escaping, leading to XSS. | |||||
| CVE-2019-9751 | 1 Otrs | 1 Otrs | 2019-03-15 | 3.5 LOW | 4.8 MEDIUM |
| An issue was discovered in Open Ticket Request System (OTRS) 6.x before 6.0.17 and 7.x before 7.0.5. An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS. This is related to Kernel/Output/Template/Document.pm. | |||||
| CVE-2017-9061 | 2 Debian, Wordpress | 2 Debian Linux, Wordpress | 2019-03-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename. | |||||
| CVE-2017-9063 | 2 Debian, Wordpress | 2 Debian Linux, Wordpress | 2019-03-15 | 4.3 MEDIUM | 6.1 MEDIUM |
| In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session. | |||||
| CVE-2017-8514 | 1 Microsoft | 1 Sharepoint Enterprise Server | 2019-03-14 | 3.5 LOW | 5.4 MEDIUM |
| An information disclosure vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Microsoft SharePoint Reflective XSS Vulnerability". | |||||
| CVE-2018-11690 | 1 Balbooa | 1 Gridbox | 2019-03-14 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. | |||||
| CVE-2017-9140 | 1 Progress | 2 Sitefinity Cms, Telerik Reporting | 2019-03-14 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to Telerik.ReportViewer.axd. | |||||
| CVE-2019-8953 | 1 Netgate | 1 Haproxy | 2019-03-14 | 4.3 MEDIUM | 6.1 MEDIUM |
| The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php and haproxy_listeners_edit.php. | |||||
| CVE-2017-1000023 | 1 Logicaldoc | 1 Logicaldoc | 2019-03-14 | 3.5 LOW | 5.4 MEDIUM |
| LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document. | |||||
| CVE-2017-15568 | 2 Debian, Redmine | 2 Debian Linux, Redmine | 2019-03-14 | 4.3 MEDIUM | 6.1 MEDIUM |
| In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of issue history. | |||||
| CVE-2017-15569 | 2 Debian, Redmine | 2 Debian Linux, Redmine | 2019-03-14 | 4.3 MEDIUM | 6.1 MEDIUM |
| In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of an issue list. | |||||
| CVE-2017-15570 | 2 Debian, Redmine | 2 Debian Linux, Redmine | 2019-03-14 | 4.3 MEDIUM | 6.1 MEDIUM |
| In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data. | |||||
| CVE-2017-15571 | 2 Debian, Redmine | 2 Debian Linux, Redmine | 2019-03-14 | 4.3 MEDIUM | 6.1 MEDIUM |
| In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data. | |||||
| CVE-2017-15573 | 2 Debian, Redmine | 2 Debian Linux, Redmine | 2019-03-14 | 4.3 MEDIUM | 6.1 MEDIUM |
| In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content. | |||||
| CVE-2017-15574 | 2 Debian, Redmine | 2 Debian Linux, Redmine | 2019-03-14 | 4.3 MEDIUM | 6.1 MEDIUM |
| In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment. | |||||
| CVE-2017-15727 | 1 Phpmyfaq | 1 Phpmyfaq | 2019-03-14 | 3.5 LOW | 5.4 MEDIUM |
| In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment. | |||||
| CVE-2019-9765 | 1 Blog Mini Project | 1 Blog Mini | 2019-03-14 | 4.3 MEDIUM | 6.1 MEDIUM |
| In Blog_mini 1.0, XSS exists via the author name of a comment reply in the app/main/views.py articleDetails() function, related to app/templates/_article_comments.html. | |||||
| CVE-2017-6099 | 1 Paypal | 1 Merchant-sdk-php | 2019-03-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter. | |||||
| CVE-2017-6102 | 1 Rockhoist Badges Project | 1 Rockhoist Badges Plugin | 2019-03-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| Persistent XSS in wordpress plugin rockhoist-badges v1.2.2. | |||||
| CVE-2015-4591 | 1 Eclinicalworks | 1 Population Health | 2019-03-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remote unauthenticated users to inject arbitrary javascript via the strMessage parameter. | |||||
| CVE-2017-14522 | 1 Wondercms | 1 Wondercms | 2019-03-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| ** DISPUTED ** In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript. NOTE: the vendor disputes this issue stating that this is a feature that enables only a logged in administrator to write execute JavaScript anywhere on their website. | |||||
| CVE-2019-9558 | 1 Mailtraq | 1 Webmail | 2019-03-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| Mailtraq WebMail version 2.17.7.3550 has Persistent Cross Site Scripting (XSS) via the body of an e-mail message. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an iframe. | |||||
| CVE-2019-9725 | 1 Korenix | 5 Jetport 5601, Jetport 5601 Firmware, Jetport 5601f and 2 more | 2019-03-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Web manager (aka Commander) on Korenix JetPort 5601 and 5601f devices has Persistent XSS via the Port Alias field under Serial Setting. | |||||
| CVE-2019-0269 | 1 Sap | 1 Businessobjects Business Intelligence | 2019-03-13 | 3.5 LOW | 5.4 MEDIUM |
| SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.10 and 4.20, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. | |||||
| CVE-2019-5925 | 1 Dradisframework | 1 Dradis | 2019-03-13 | 3.5 LOW | 5.4 MEDIUM |
| Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Professional Edition v3.1.1 and earlier allow remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
| CVE-2019-9557 | 1 Codecrafters | 1 Ability Mail Server | 2019-03-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an iframe. | |||||
| CVE-2019-9736 | 1 1024tools | 1 1024tools | 2019-03-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| DOM-based XSS exists in 1024Tools Markdown 1.0 via vectors involving the '<EMBED SRC="data:image/svg+xml' substring. | |||||
| CVE-2019-9738 | 1 Golangtc | 1 Gopher | 2019-03-13 | 4.3 MEDIUM | 6.1 MEDIUM |
| jimmykuu Gopher 2.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring. | |||||
| CVE-2017-6003 | 1 Dotcms | 1 Dotcms | 2019-03-12 | 4.3 MEDIUM | 6.1 MEDIUM |
| dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields. | |||||
| CVE-2017-5962 | 1 Netresearch | 1 Contexts Wurfl | 2019-03-12 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in contexts_wurfl (for TYPO3) before 0.4.2. The vulnerability exists due to insufficient filtration of user-supplied data in the "force_ua" HTTP GET parameter passed to the "/contexts_wurfl/Library/wurfl-dbapi-1.4.4.0/check_wurfl.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | |||||
| CVE-2019-9646 | 1 Codepeople | 1 Contact Form Email | 2019-03-12 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area." | |||||
| CVE-2019-9580 | 1 Stackstorm | 1 Stackstorm | 2019-03-12 | 4.3 MEDIUM | 6.1 MEDIUM |
| In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mechanism via a "null" origin value, potentially leading to XSS. | |||||
| CVE-2017-5827 | 1 Hp | 1 Aruba Clearpass Policy Manager | 2019-03-11 | 3.5 LOW | 5.4 MEDIUM |
| A reflected cross site scripting vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found. | |||||
| CVE-2019-9660 | 1 Yzmcms | 1 Yzmcms | 2019-03-11 | 3.5 LOW | 4.8 MEDIUM |
| Stored XSS exists in YzmCMS 5.2 via the admin/category/edit.html "catname" parameter. | |||||
| CVE-2019-9661 | 1 Yzmcms | 1 Yzmcms | 2019-03-11 | 3.5 LOW | 4.8 MEDIUM |
| Stored XSS exists in YzmCMS 5.2 via the admin/system_manage/user_config_edit.html "value" parameter, | |||||
| CVE-2017-5963 | 1 Caddy Project | 1 Caddy | 2019-03-08 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy/Resources/Public/JavaScript/e-payment/paymill/api/php/payment.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | |||||
| CVE-2018-14499 | 1 Hyphp | 1 Hybbs | 2019-03-08 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was found in HYBBS through 2016-03-08. There is an XSS vulnerablity via an article title to post.html. | |||||
| CVE-2018-16804 | 1 Ucms Project | 1 Ucms | 2019-03-08 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in UCMS 1.4.6. There is XSS in the title bar, as demonstrated by a do=list request. | |||||
