Vulnerabilities (CVE)

Filtered by CWE-79
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-12544 3 Hp, Linux, Microsoft 3 System Management Homepage, Linux Kernel, Windows 2018-03-02 3.5 LOW 5.4 MEDIUM
A cross-site scripting vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.
CVE-2018-6866 1 Learning And Examination Management System Script Project 1 Learning And Examination Management System Script 2018-03-01 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in PHP Scripts Mall Learning and Examination Management System Script 2.3.1 via a crafted message.
CVE-2018-6867 1 Alibaba Clone Script Project 1 Alibaba Clone Script 2018-03-01 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in PHP Scripts Mall Alibaba Clone Script 1.0.2 via a profile parameter.
CVE-2018-6868 1 Groupon Clone Script Project 1 Groupon Clone Script 2018-03-01 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in PHP Scripts Mall Slickdeals / DealNews / Groupon Clone Script 3.0.2 via a User Profile Field parameter.
CVE-2016-8532 1 Hp 1 Matrix Operating Environment 2018-03-01 3.5 LOW 5.4 MEDIUM
A cross site scripting vulnerability in HPE Matrix Operating Environment version 7.6 was found.
CVE-2018-1000020 1 Open-emr 1 Openemr 2018-03-01 4.3 MEDIUM 6.1 MEDIUM
OpenEMR version 5.0.0 contains a Cross Site Scripting (XSS) vulnerability in open-flash-chart.swf and _posteddata.php that can result in . This vulnerability appears to have been fixed in 5.0.0 Patch 2 or higher.
CVE-2018-6795 1 Naukri Clone Script Project 1 Naukri Clone Script 2018-03-01 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall Naukri Clone Script 3.0.3 has Stored XSS via every profile input field.
CVE-2018-6878 1 Hot Scripts Clone Project 1 Hot Scripts Clone 2018-03-01 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in the review section in PHP Scripts Mall Hot Scripts Clone Script Classified 3.1 via the title or description field.
CVE-2018-6468 1 Flickrrss Project 1 Flickrrss 2018-02-28 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_id parameter to wp-admin/options-general.php.
CVE-2018-6466 1 Flickrrss Project 1 Flickrrss 2018-02-28 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_set parameter to wp-admin/options-general.php.
CVE-2018-6469 1 Flickrrss Project 1 Flickrrss 2018-02-28 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the flickrRSS_tags parameter to wp-admin/options-general.php.
CVE-2018-6824 1 Cozy 1 Cozy 2018-02-27 4.3 MEDIUM 6.1 MEDIUM
Cozy version 2 has XSS allowing remote attackers to obtain administrative access via JavaScript code in the url parameter to the /api/proxy URI, as demonstrated by an XMLHttpRequest call with an 'email:"attacker@example.com"' request, which can be followed by a password reset.
CVE-2018-5306 1 Sonatype 1 Nexus Repository Manager 2018-02-27 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 3.x before 3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the repoId or (2) format parameter to service/siesta/healthcheck/healthCheckFileDetail/.../index.html; (3) the filename in the "File Upload" functionality of the Staging Upload; (4) the username when creating a new user; or (5) the IQ Server URL field in the IQ Server Connection functionality.
CVE-2012-0941 1 Fortinet 1 Fortios 2018-02-27 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Endpoint Monitor, (2) Dialup List, or (3) Log&Report Display modules, or the fields_sorted_opt parameter to (4) user/auth/list or (5) endpointcompliance/app_detect/predefined_sig_list.
CVE-2012-6346 1 Fortinet 1 Fortiweb 2018-02-27 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in FortiWeb before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) redir or (2) mkey parameter to waf/pcre_expression/validate.
CVE-2018-5307 1 Sonatype 1 Nexus Repository Manager 2018-02-27 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 2.x before 2.14.6 allow remote attackers to inject arbitrary web script or HTML via (1) the repoId or (2) format parameter to service/siesta/healthcheck/healthCheckFileDetail/.../index.html; (3) the filename in the "File Upload" functionality of the Staging Upload; (4) the username when creating a new user; or (5) the IQ Server URL field in the IQ Server Connection functionality.
CVE-2018-6891 1 Ladela 1 Bookly 2018-02-27 4.3 MEDIUM 6.1 MEDIUM
Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js.
CVE-2012-6347 1 Fortinet 1 Fortidb 2018-02-27 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Java number format exception handling in FortiGate FortiDB before 4.4.2 allow remote attackers to inject arbitrary web script or HTML via the conversationContext parameter to (1) admin/auditTrail.jsf, (2) mapolicymgmt/targetsMonitorView.jsf, (3) vascan/globalsummary.jsf, (4) vaerrorlog/vaErrorLog.jsf, (5) database/listTargetGroups.jsf, (6) sysconfig/listSystemInfo.jsf, (7) vascan/list.jsf, (8) network/router.jsf, (9) mapolicymgmt/editPolicyProfile.jsf, or (10) mapolicymgmt/maPolicyMasterList.jsf.
CVE-2018-2383 1 Sap 1 Internet Graphics Server 2018-02-27 4.3 MEDIUM 6.1 MEDIUM
Reflected cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.
CVE-2018-2388 1 Sap 1 Internet Graphics Server 2018-02-27 4.3 MEDIUM 6.1 MEDIUM
Stored cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.
CVE-2017-1000506 1 Mautic 1 Mautic 2018-02-26 4.3 MEDIUM 6.1 MEDIUM
Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code.
CVE-2017-1000510 1 Croogo 1 Croogo 2018-02-26 3.5 LOW 5.4 MEDIUM
Croogo version 2.3.1-17-g6f82e6c contains a Cross Site Scripting (XSS) vulnerability in Page name that can result in execution of javascript code.
CVE-2017-1000509 1 Dolibarr 1 Dolibarr 2018-02-26 3.5 LOW 5.4 MEDIUM
Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.
CVE-2017-1000508 1 Invoiceplane 1 Invoiceplane 2018-02-26 4.3 MEDIUM 6.1 MEDIUM
Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later.
CVE-2017-1000507 1 Cnvs 1 Canvas 2018-02-26 3.5 LOW 5.4 MEDIUM
Canvs Canvas version 3.4.2 contains a Cross Site Scripting (XSS) vulnerability in User's details that can result in denial of service and execution of javascript code.
CVE-2018-6796 1 Multilanguage Real Estate Mlm Script Project 1 Multilanguage Real Estate Mlm Script 2018-02-26 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall Multilanguage Real Estate MLM Script 3.0 has Stored XSS via every profile input field.
CVE-2018-6655 1 Doctor Search Script Project 1 Doctor Search Script 2018-02-26 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall Doctor Search Script 1.0.2 has Stored XSS via an arbitrary profile field.
CVE-2017-1761 1 Ibm 1 Websphere Portal 2018-02-26 4.3 MEDIUM 6.1 MEDIUM
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136005.
CVE-2018-1382 1 Ibm 1 Api Connect 2018-02-26 3.5 LOW 5.4 MEDIUM
IBM API Connect 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138079.
CVE-2018-6864 1 Multireligion Responsive Matrimonial Project 1 Multireligion Responsive Matrimonial 2018-02-26 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in PHP Scripts Mall Multi religion Responsive Matrimonial 4.7.2 via a user profile update parameter.
CVE-2018-6862 1 Bitcoin Mlm Project 1 Bitcoin Mlm 2018-02-26 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) exists in PHP Scripts Mall Bitcoin MLM Software 1.0.2 via a profile field.
CVE-2018-1401 1 Ibm 1 Websphere Portal 2018-02-26 4.3 MEDIUM 6.1 MEDIUM
IBM WebSphere Portal 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138437.
CVE-2018-6844 1 Mybb 1 Mybb 2018-02-26 3.5 LOW 5.4 MEDIUM
MyBB 1.8.14 has XSS via the Title or Description field on the Edit Forum screen.
CVE-2018-6834 1 Etherpad 1 Etherpad Lite 2018-02-26 4.3 MEDIUM 6.1 MEDIUM
static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.
CVE-2015-2329 1 Woocommerce 1 Woocommerce 2018-02-26 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted order.
CVE-2015-3618 1 Nagios 1 Business Process Intelligence 2018-02-26 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving index.php.
CVE-2015-3619 1 Virtuemart 1 Virtuemart 2018-02-26 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in assets/js/vm2admin.js in the VirtueMart component before 3.0.8 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors involving a "double encode combination of first_name, last_name and company."
CVE-2018-6291 1 Kaspersky 1 Secure Mail Gateway 2018-02-23 4.3 MEDIUM 6.1 MEDIUM
WebConsole Cross-Site Scripting in Kaspersky Secure Mail Gateway version 1.1.
CVE-2017-5124 2 Debian, Google 2 Debian Linux, Chrome 2018-02-23 4.3 MEDIUM 6.1 MEDIUM
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.
CVE-2017-8783 1 Synacor 1 Zimbra Collaboration Suite 2018-02-23 3.5 LOW 5.4 MEDIUM
Synacor Zimbra Collaboration Suite (ZCS) before 8.7.10 has Persistent XSS.
CVE-2017-17703 1 Synacor 1 Zimbra Collaboration Suite 2018-02-23 4.3 MEDIUM 6.1 MEDIUM
Synacor Zimbra Collaboration Suite (ZCS) before 8.8.3 has Persistent XSS.
CVE-2016-6319 1 Theforeman 1 Foreman 2018-02-23 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in app/helpers/form_helper.rb in Foreman before 1.12.2, as used by Remote Execution and possibly other plugins, allows remote attackers to inject arbitrary web script or HTML via the label parameter.
CVE-2018-6355 1 Iball 2 Ib-wrb302n, Ib-wrb302n Firmware 2018-02-21 4.3 MEDIUM 6.1 MEDIUM
/goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 2017" firmware has Unauthenticated Stored Cross Site Scripting via the lang parameter.
CVE-2016-4317 1 Atlassian 1 Confluence 2018-02-16 3.5 LOW 5.4 MEDIUM
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
CVE-2016-4318 1 Atlassian 1 Jira 2018-02-16 3.5 LOW 4.8 MEDIUM
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.
CVE-2018-6354 1 Formspree 1 Formspree 2018-02-15 4.3 MEDIUM 6.1 MEDIUM
templates/forms/thanks.html in Formspree before 2018-01-23 allows XSS related to the _next parameter.
CVE-2018-6465 1 Wp-property-hive 1 Propertyhive 2018-02-15 4.3 MEDIUM 6.1 MEDIUM
The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php.
CVE-2017-18083 1 Atlassian 1 Confluence 2018-02-15 3.5 LOW 5.4 MEDIUM
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.
CVE-2018-6561 1 Dojotoolkit 1 Dojo 2018-02-15 4.3 MEDIUM 6.1 MEDIUM
dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.
CVE-2016-0303 1 Ibm 1 Tivoli Integrated Portal 2018-02-15 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.