Vulnerabilities (CVE)

Filtered by CWE-79
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-12813 1 Stivasoft 1 Phpjabbers File Sharing Script 2018-01-11 4.3 MEDIUM 6.1 MEDIUM
PHPJabbers File Sharing Script 1.0 has stored XSS in the comments section.
CVE-2017-12812 1 Stivasoft 1 Phpjabbers Night Club Booking Software 2018-01-11 4.3 MEDIUM 6.1 MEDIUM
PHPJabbers Night Club Booking Software has stored XSS in the name parameter in the reservations tab.
CVE-2017-18012 1 Z-url Preview Project 1 Z-url Preview 2018-01-11 4.3 MEDIUM 6.1 MEDIUM
The Z-URL Preview plugin 1.6.1 for WordPress has XSS via the class.zlinkpreview.php url parameter.
CVE-2017-18004 1 Zurmo 1 Zurmo Crm 2018-01-11 3.5 LOW 5.4 MEDIUM
Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint.
CVE-2015-7324 1 Stackideas 1 Komento 2018-01-11 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) img or (2) url tag of a new comment.
CVE-2017-17911 1 Archon 1 Archon 2018-01-11 4.3 MEDIUM 6.1 MEDIUM
packages/core/contact.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?p=core/contact request, aka Open Bug Bounty ID OBB-278503.
CVE-2017-17869 1 Mgl-instagram-gallery Project 1 Mgl-instagram-gallery 2018-01-10 4.3 MEDIUM 6.1 MEDIUM
The mgl-instagram-gallery plugin for WordPress has XSS via the single-gallery.php media parameter.
CVE-2017-17909 1 Responsive Realestate Script Project 1 Responsive Realestate Script 2018-01-10 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Responsive Realestate Script has XSS via the admin/general.php gplus parameter.
CVE-2017-16876 2 Fedoraproject, Mistune Project 2 Fedora, Mistune 2018-01-10 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.
CVE-2017-16768 1 Synology 1 Mailplus Server 2018-01-10 3.5 LOW 4.8 MEDIUM
Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter.
CVE-2017-17937 1 Vanguard Project 1 Marketplace Digital Products Php 2018-01-10 4.3 MEDIUM 6.1 MEDIUM
Vanguard Marketplace Digital Products PHP has XSS via the phps_query parameter to /search.
CVE-2017-17929 1 Ordermanagementscript 1 Professional Service Script 2018-01-10 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Professional Service Script has XSS via the admin/bannerview.php view parameter.
CVE-2017-17925 1 Ordermanagementscript 1 Professional Service Script 2018-01-10 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Professional Service Script has XSS via the admin/general_settingupd.php website_title parameter.
CVE-2017-17988 1 Muslim Matrimonial Script Project 1 Muslim Matrimonial Script 2018-01-09 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_add.php event_title parameter.
CVE-2017-17986 1 Muslim Matrimonial Script Project 1 Muslim Matrimonial Script 2018-01-09 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/caste_view.php comm_id parameter.
CVE-2017-17984 1 Muslim Matrimonial Script Project 1 Muslim Matrimonial Script 2018-01-09 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_edit.php edit_id parameter.
CVE-2017-17985 1 Muslim Matrimonial Script Project 1 Muslim Matrimonial Script 2018-01-09 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/state_view.php cou_id parameter.
CVE-2017-17981 1 Muslim Matrimonial Script Project 1 Muslim Matrimonial Script 2018-01-09 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/slider_edit.php edit_id parameter.
CVE-2017-17940 1 Single Theater Booking Script Project 1 Single Theater Booking Script 2018-01-09 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Single Theater Booking has XSS via the title parameter to admin/sitesettings.php.
CVE-2017-17938 1 Single Theater Booking Script Project 1 Single Theater Booking Script 2018-01-09 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Single Theater Booking has XSS via the admin/viewtheatre.php theatreid parameter.
CVE-2017-17904 1 Fortunescripts 1 Lynda Clone 2018-01-09 3.5 LOW 5.4 MEDIUM
FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the edit_profile_first_name parameter to user/edit_profile.
CVE-2017-17893 1 Readymade Video Sharing Script Project 1 Readymade Video Sharing Script 2018-01-09 4.3 MEDIUM 6.1 MEDIUM
Readymade Video Sharing Script has XSS via the search_video.php search parameter, the viewsubs.php chnlid parameter, or the user-profile-edit.php fname parameter.
CVE-2017-17868 1 Liferay 1 Liferay Portal 2018-01-09 4.3 MEDIUM 6.1 MEDIUM
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
CVE-2017-17907 1 Car Rental Script Project 1 Car Rental Script 2018-01-09 4.3 MEDIUM 6.1 MEDIUM
PHP Scripts Mall Car Rental Script has XSS via the admin/areaedit.php carid parameter or the admin/sitesettings.php websitename parameter.
CVE-2017-17896 1 Basic Job Site Script Project 1 Basic Job Site Script 2018-01-09 4.3 MEDIUM 6.1 MEDIUM
Readymade Job Site Script has XSS via the keyword parameter to the /job URI.
CVE-2017-17994 1 Iwcnetwork 1 Biometric Shift Employee Management System 2018-01-09 3.5 LOW 5.4 MEDIUM
Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria request.
CVE-2017-17995 1 Iwcnetwork 1 Biometric Shift Employee Management System 2018-01-09 3.5 LOW 5.4 MEDIUM
Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.
CVE-2017-17993 1 Iwcnetwork 1 Biometric Shift Employee Management System 2018-01-09 3.5 LOW 5.4 MEDIUM
Biometric Shift Employee Management System has XSS via the amount parameter in an index.php?user=addition_deduction request.
CVE-2017-17991 1 Iwcnetwork 1 Biometric Shift Employee Management System 2018-01-09 3.5 LOW 5.4 MEDIUM
Biometric Shift Employee Management System has XSS via the expense_name parameter in an index.php?user=expenses request.
CVE-2017-17989 1 Iwcnetwork 1 Biometric Shift Employee Management System 2018-01-09 3.5 LOW 5.4 MEDIUM
Biometric Shift Employee Management System has XSS via the index.php holiday_name parameter in an edit_holiday action.
CVE-2017-17744 1 Webdesi9 1 Custom Map 2018-01-08 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the custom-map plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter to view/advancedsettings.php.
CVE-2017-17719 1 Olyos 1 Wp-concours 2018-01-08 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the wp-concours plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the result_message parameter to includes/concours_page.php.
CVE-2017-17752 1 Codecrafters 1 Ability Mail Server 2018-01-08 4.3 MEDIUM 6.1 MEDIUM
Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is fixed in version 4.2.4.
CVE-2017-1751 1 Ibm 1 Robotic Process Automation With Automation Anywhere 2018-01-05 3.5 LOW 5.4 MEDIUM
IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 135546.
CVE-2011-4955 1 Bsuite Project 1 Bsuite 2018-01-05 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in ui_stats.php in the bSuite plugin before 5 alpha 3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s or (2) p parameters to index.php.
CVE-2017-17745 1 Tp-link 2 Tl-sg108e, Tl-sg108e Firmware 2018-01-05 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to submit arbitrary java script via the 'sysName' parameter.
CVE-2017-17775 1 Piwigo 1 Piwigo 2018-01-05 4.3 MEDIUM 6.1 MEDIUM
Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.
CVE-2017-17753 1 Csv-import-export Project 1 Csv-import-export 2018-01-05 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the esb-csv-import-export plugin through 1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cie_type, (2) cie_import, (3) cie_update, or (4) cie_ignore parameter to includes/admin/views/esb-cie-import-export-page.php.
CVE-2013-6465 1 Redhat 1 Jbpm 2018-01-05 3.5 LOW 5.4 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HTML via vectors related to task name html inputs.
CVE-2017-12630 1 Apache 1 Drill 2018-01-05 3.5 LOW 5.4 MEDIUM
In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Query page, malicious user may obtain this information from Profile page afterwards.
CVE-2017-5008 1 Google 1 Chrome 2018-01-05 4.3 MEDIUM 6.1 MEDIUM
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed attacker controlled JavaScript to be run during the invocation of a private script method, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
CVE-2017-5085 2 Apple, Google 2 Iphone Os, Chrome 2018-01-05 4.3 MEDIUM 6.1 MEDIUM
Inappropriate implementation in Bookmarks in Google Chrome prior to 59 for iOS allowed a remote attacker who convinced the user to perform certain operations to run JavaScript on chrome:// pages via a crafted bookmark.
CVE-2017-5007 1 Google 1 Chrome 2018-01-05 4.3 MEDIUM 6.1 MEDIUM
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled the sequence of events when closing a page, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
CVE-2017-5010 1 Google 1 Chrome 2018-01-05 4.3 MEDIUM 6.1 MEDIUM
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, resolved promises in an inappropriate context, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
CVE-2016-6320 1 Theforeman 1 Foreman 2018-01-05 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in app/assets/javascripts/host_edit_interfaces.js in Foreman before 1.12.2 allows remote authenticated users to inject arbitrary web script or HTML via the network interface device identifier in the host interface form.
CVE-2017-5018 1 Google 1 Chrome 2018-01-05 4.3 MEDIUM 6.1 MEDIUM
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, had an insufficiently strict content security policy on the Chrome app launcher page, which allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page.
CVE-2017-5020 1 Google 1 Chrome 2018-01-05 4.3 MEDIUM 6.1 MEDIUM
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to require a user gesture for powerful download operations, which allowed a remote attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted HTML page.
CVE-2017-7400 1 Openstack 1 Horizon 2018-01-05 3.5 LOW 4.8 MEDIUM
OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
CVE-2016-7033 1 Redhat 1 Jboss Bpm Suite 2018-01-05 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-5006 1 Google 1 Chrome 2018-01-05 4.3 MEDIUM 6.1 MEDIUM
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled object owner relationships, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.