Vulnerabilities (CVE)

Filtered by CWE-79
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24505 1 Madeit 1 Forms 2021-08-17 3.5 LOW 5.4 MEDIUM
The Forms WordPress plugin before 1.12.3 did not sanitise its input fields, leading to Stored Cross-Site scripting issues. The plugin was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the Forms "Add new" field.
CVE-2021-37633 1 Discourse 1 Discourse 2021-08-17 4.3 MEDIUM 6.1 MEDIUM
Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susceptible to XSS attacks. This vulnerability only affects sites which have modified or disabled Discourse's default Content Security Policy. This issue is patched in the latest `stable` 2.7.8 version of Discourse. As a workaround users may ensure that the Content Security Policy is enabled, and has not been modified in a way which would make it more vulnerable to XSS attacks.
CVE-2021-24509 1 A3rev 1 Page View Count 2021-08-17 3.5 LOW 5.4 MEDIUM
The Page View Count WordPress plugin before 2.4.9 does not escape the postid parameter of pvc_stats shortcode, allowing users with a role as low as Contributor to perform Stored XSS attacks. A post made by a contributor would still have to be approved by an admin to have the XSS triggered in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability.
CVE-2020-8263 1 Pulsesecure 1 Pulse Secure Desktop Client 2021-08-17 3.5 LOW 5.4 MEDIUM
A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) through the CGI file.
CVE-2021-24522 1 Profilepress 1 Profilepress 2021-08-17 4.3 MEDIUM 6.1 MEDIUM
The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to wp-admin access. Further, the plugin in several places assigned $_POST as $_GET which meant that in some cases this could be replicated with just $_GET parameters and no need for $_POST values.
CVE-2021-37211 1 Larvata 1 Flygo 2021-08-17 3.5 LOW 5.4 MEDIUM
The bulletin function of Flygo does not filter special characters while a new announcement is added. Remoter attackers can use the vulnerability with general user’s credential to inject JavaScript and execute stored XSS attacks.
CVE-2013-4718 1 Otrs 2 Otrs, Otrs Itsm 2021-08-17 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) ITSM 3.0.x before 3.0.9, 3.1.x before 3.1.10, and 3.2.x before 3.2.7 allows remote authenticated users to inject arbitrary web script or HTML via an ITSM ConfigItem search.
CVE-2021-37390 1 Chamilo 1 Chamilo Lms 2021-08-17 4.3 MEDIUM 6.1 MEDIUM
A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).
CVE-2021-24304 1 Tagdiv 1 Newsmag 2021-08-17 4.3 MEDIUM 6.1 MEDIUM
The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.
CVE-2021-37389 1 Chamilo 1 Chamilo 2021-08-17 4.3 MEDIUM 6.1 MEDIUM
Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.
CVE-2021-37573 1 Tiny Java Web Server Project 1 Tiny Java Web Server 2021-08-17 4.3 MEDIUM 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in the web server TTiny Java Web Server and Servlet Container (TJWS) <=1.115 allows an adversary to inject malicious code on the server's "404 Page not Found" error page
CVE-2021-34660 1 Verygoodplugins 1 Wp Fusion 2021-08-16 4.3 MEDIUM 6.1 MEDIUM
The WP Fusion Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the startdate parameter found in the ~/includes/admin/logging/class-log-table-list.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.37.18.
CVE-2021-37634 1 Vapor 1 Leafkit 2021-08-16 4.3 MEDIUM 6.1 MEDIUM
Leafkit is a templating language with Swift-inspired syntax. Versions prior to 1.3.0 are susceptible to Cross-site Scripting (XSS) attacks. This affects anyone passing unsanitised data to Leaf's variable tags. Before this fix, Leaf would not escape any strings passed to tags as variables. If an attacker managed to find a variable that was rendered with their unsanitised data, they could inject scripts into a generated Leaf page, which could enable XSS attacks if other mitigations such as a Content Security Policy were not enabled. This has been patched in 1.3.0. As a workaround sanitize any untrusted input before passing it to Leaf and enable a CSP to block inline script and CSS data.
CVE-2020-20990 1 Domainmod 1 Domainmod 2021-08-16 3.5 LOW 5.4 MEDIUM
A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via the Segment Name parameter.
CVE-2020-20988 1 Domainmod 1 Domainmod 2021-08-16 3.5 LOW 5.4 MEDIUM
A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "or Expiring Between" parameter.
CVE-2021-38602 1 Pluxml 1 Pluxml 2021-08-16 3.5 LOW 4.8 MEDIUM
PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.
CVE-2021-38603 1 Pluxml 1 Pluxml 2021-08-16 3.5 LOW 4.8 MEDIUM
PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.
CVE-2021-31655 1 Trendnet 2 Tv-ip110wn, Tv-ip110wn Firmware 2021-08-16 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in TRENDnet TV-IP110WN V1.2.2.64 V1.2.2.65 V1.2.2.68 via the profile parameter. in a GET request in view.cgi.
CVE-2021-37152 1 Sonatype 1 Nexus Repository Manager 2021-08-16 3.5 LOW 5.4 MEDIUM
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.
CVE-2020-18456 1 Pbootcms 1 Pbootcms 2021-08-16 3.5 LOW 4.8 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php.
CVE-2021-38193 1 Ammonia Project 1 Ammonia 2021-08-16 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870.
CVE-2021-38186 1 Comrak Project 1 Comrak 2021-08-14 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in the comrak crate before 0.10.1 for Rust. It mishandles & characters, leading to XSS via &# HTML entities.
CVE-2018-17861 1 Sap 1 J2ee Engine 2021-08-13 4.3 MEDIUM 6.1 MEDIUM
** UNSUPPORTED WHEN ASSIGNED ** A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Portal/EPP allows remote attackers to inject arbitrary web script via the wsdlLib parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2018-17862 1 Sap 1 J2ee Engine 2021-08-13 4.3 MEDIUM 6.1 MEDIUM
** UNSUPPORTED WHEN ASSIGNED ** A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Fiori allows remote attackers to inject arbitrary web script via the sys_jdbc parameter to /TestJDBC_Web/test2. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2018-17865 1 Sap 1 J2ee Engine 2021-08-13 4.3 MEDIUM 6.1 MEDIUM
** UNSUPPORTED WHEN ASSIGNED ** A cross-site scripting (XSS) vulnerability in SAP J2EE Engine 7.01 allows remote attackers to inject arbitrary web script via the wsdlPath parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2020-18693 1 Mineweb Project 1 Minewebcms 2021-08-13 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious code into the 'Title' field of the component '/admin/news'.
CVE-2020-21362 1 Maccms 1 Maccms 2021-08-13 3.5 LOW 5.4 MEDIUM
A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arbitrary web scripts or HTML via the 'wd' parameter.
CVE-2020-20977 1 Ukcms Project 1 Ukcms 2021-08-13 3.5 LOW 5.4 MEDIUM
A stored cross site scripting (XSS) vulnerability in index.php/legend/6.html of UK CMS v1.1.10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Comments section.
CVE-2020-21929 1 Eyoucms 1 Eyoucms 2021-08-13 3.5 LOW 5.4 MEDIUM
A stored cross site scripting (XSS) vulnerability in the web_copyright field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML.
CVE-2020-21930 1 Eyoucms 1 Eyoucms 2021-08-13 3.5 LOW 5.4 MEDIUM
A stored cross site scripting (XSS) vulnerability in the web_attr_2 field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML.
CVE-2020-18446 1 Yunucms 1 Yunucms 2021-08-13 3.5 LOW 4.8 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php.
CVE-2020-18449 1 Ukcms 1 Ukcms 2021-08-13 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in UKCMS v1.1.10 via data in the index function in Single.php
CVE-2020-18445 1 Yunucms 1 Yunucms 2021-08-13 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php.
CVE-2020-18451 1 Damicms 1 Damicms 2021-08-13 3.5 LOW 4.8 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in DamiCMS v6.0.6 via the title parameter in the doadd function in LabelAction.class.php.
CVE-2021-32597 1 Fortinet 2 Fortianalyzer, Fortimanager 2021-08-13 3.5 LOW 5.4 MEDIUM
Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions 7.0.0, 6.4.5 and below, 6.2.7 and below user interface, may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious payload in GET parameters.
CVE-2021-38157 1 Leostream 1 Connection Broker 2021-08-13 4.3 MEDIUM 6.1 MEDIUM
** UNSUPPORTED WHEN ASSIGNED ** LeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2021-37365 1 Ctparental Project 1 Ctparental 2021-08-13 4.3 MEDIUM 6.1 MEDIUM
CTparental before 4.45.03 is vulnerable to cross-site scripting (XSS) in the CTparental admin panel. In bl_categires_help.php, the 'categories' variable is assigned with the content of the query string param 'cat' without sanitization or encoding, enabling an attacker to inject malicious code into the output webpage.
CVE-2021-35030 1 Zyxel 24 Gs1900-10hp, Gs1900-10hp Firmware, Gs1900-16 and 21 more 2021-08-13 2.3 LOW 4.3 MEDIUM
A vulnerability was found in the CGI program in Zyxel GS1900-8 firmware version V2.60, that did not properly sterilize packet contents and could allow an authenticated, local user to perform a cross-site scripting (XSS) attack via a crafted LLDP packet.
CVE-2016-0919 1 Rsa 1 Web Threat Detection 2021-08-12 4.3 MEDIUM 6.1 MEDIUM
EMC RSA Web Threat Detection version 5.0, RSA Web Threat Detection version 5.1, RSA Web Threat Detection version 5.1.2 has a cross site scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system.
CVE-2017-8041 1 Vmware 1 Single Sign-on For Pivotal Cloud Foundry 2021-08-12 4.3 MEDIUM 6.1 MEDIUM
In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS attack on certain Single Sign-On service UI pages by inputting code in the text field for an organization name.
CVE-2017-8044 1 Vmware 1 Single Sign-on For Pivotal Cloud Foundry 2021-08-12 4.3 MEDIUM 6.1 MEDIUM
In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading to XSS attacks.
CVE-2021-28833 1 Increments 1 Qiita\ 2021-08-12 4.3 MEDIUM 6.1 MEDIUM
Increments Qiita::Markdown before 0.34.0 allows XSS via a crafted gist link, a different vulnerability than CVE-2021-28796.
CVE-2021-24320 1 Bold-themes 1 Bello 2021-08-12 4.3 MEDIUM 6.1 MEDIUM
The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view, bt_bb_listing_field_my_lat, bt_bb_listing_field_my_lng, bt_bb_listing_field_distance_value, bt_bb_listing_field_my_lat_default, bt_bb_listing_field_keyword, bt_bb_listing_field_location_autocomplete, bt_bb_listing_field_price_range_from and bt_bb_listing_field_price_range_to parameter in ints listing page, leading to reflected Cross-Site Scripting issues.
CVE-2021-24319 1 Bold-themes 1 Bello 2021-08-12 3.5 LOW 5.4 MEDIUM
The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before outputting it back in the shop/my-account/bello-listing-endpoint/ page, leading to a Cross-Site Scripting issue
CVE-2017-10837 1 Backup-guard 1 Backup Guard 2021-08-12 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in BackupGuard prior to version 1.1.47 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
CVE-2021-38151 1 Chikitsa 1 Patient Management System 2021-08-12 3.5 LOW 5.4 MEDIUM
index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS.
CVE-2021-20116 1 Tecnick 1 Tcexam 2021-08-12 4.3 MEDIUM 6.1 MEDIUM
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supplied. An attacker could craft a malicious link which, if triggered by an administrator, could result in the attacker hijacking the victim's session or performing actions on their behalf.
CVE-2021-20115 1 Tecnick 1 Tcexam 2021-08-12 4.3 MEDIUM 6.1 MEDIUM
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supplied. An attacker could craft a malicious link which, if triggered by an administrator, could result in the attacker hijacking the victim's session or performing actions on their behalf.
CVE-2021-36454 1 Naviwebs 1 Navigate Cms 2021-08-12 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\backups.php, 2) blocks\blocks.php, 3) brands\brands.php, 4) comments\comments.php, 5) coupons\coupons.php, 6) feeds\feeds.php, 7) functions\functions.php, 8) items\items.php, 9) menus\menus.php, 10) orders\orders.php, 11) payment_methods\payment_methods.php, 12) products\products.php, 13) profiles\profiles.php, 14) shipping_methods\shipping_methods.php, 15) templates\templates.php, 16) users\users.php, 17) webdictionary\webdictionary.php, 18) websites\websites.php, and 19) webusers\webusers.php because the initial_url function is built in these files.
CVE-2021-37552 1 Jetbrains 1 Youtrack 2021-08-12 3.5 LOW 5.4 MEDIUM
In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.