Vulnerabilities (CVE)

Filtered by CWE-79
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-17450 1 Php-fusion 1 Php-fusion 2020-08-13 4.3 MEDIUM 6.1 MEDIUM
PHP-Fusion 9.03 allows XSS on the preview page.
CVE-2020-17362 1 Themeinprogress 1 Nova Lite 2020-08-13 4.3 MEDIUM 6.1 MEDIUM
search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS.
CVE-2020-15597 1 Soplanning 1 Soplanning 2020-08-13 3.5 LOW 5.4 MEDIUM
SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment field.
CVE-2020-15139 1 Mybb 1 Mybb 2020-08-13 4.3 MEDIUM 6.1 MEDIUM
In MyBB before version 1.8.24, the custom MyCode (BBCode) for the visual editor doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. The weakness can be exploited by pointing a victim to a page where the visual editor is active (e.g. as a post or Private Message) and operates on a maliciously crafted MyCode message. This may occur on pages where message content is pre-filled using a GET/POST parameter, or on reply pages where a previously saved malicious message is quoted. After upgrading MyBB to 1.8.24, make sure to update the version attribute in the `codebuttons` template for non-default themes to serve the latest version of the patched `jscripts/bbcodes_sceditor.js` file.
CVE-2020-17372 1 Sugarcrm 1 Sugarcrm 2020-08-13 3.5 LOW 5.4 MEDIUM
SugarCRM before 10.1.0 (Q3 2020) allows XSS.
CVE-2020-15071 1 Getsymphony 1 Symphony 2020-08-13 4.3 MEDIUM 6.1 MEDIUM
content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading.
CVE-2020-6300 1 Sap 1 Businessobjects Business Intelligence Platform 2020-08-13 3.5 LOW 4.8 MEDIUM
SAP Business Objects Business Intelligence Platform (Central Management Console), versions- 4.2, 4.3, allows an attacker with administrator rights can use the web application to send malicious code to a different end user (victim), as it does not sufficiently encode user-controlled inputs for RecycleBin, resulting in Stored Cross-Site Scripting (XSS) vulnerability.
CVE-2018-15913 1 Cloudera 1 Cloudera Manager 2020-08-13 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Cloudera Manager 5.x through 5.15.0. One type of page in Cloudera Manager uses a 'returnUrl' parameter to redirect the user to another page in Cloudera Manager once a wizard is completed. The validity of this parameter was not checked. As a result, the user could be automatically redirected to an attacker's external site or perform a malicious JavaScript function that results in cross-site scripting (XSS). This was fixed by not allowing any value in the returnUrl parameter with patterns such as http://, https://, //, or javascript. The only exceptions to this rule are the SAML Login/Logout URLs, which remain supported since they are explicitly configured and they are not passed via the returnUrl parameter.
CVE-2020-10777 1 Redhat 1 Cloudforms 2020-08-12 3.5 LOW 5.4 MEDIUM
A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms.
CVE-2012-4194 5 Canonical, Mozilla, Opensuse and 2 more 14 Ubuntu Linux, Firefox, Firefox Esr and 11 more 2020-08-12 4.3 MEDIUM N/A
Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 do not prevent use of the valueOf method to shadow the location object (aka window.location), which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving a plugin.
CVE-2012-4195 5 Canonical, Mozilla, Opensuse and 2 more 14 Ubuntu Linux, Firefox, Firefox Esr and 11 more 2020-08-12 4.3 MEDIUM N/A
The nsLocation::CheckURL function in Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 does not properly determine the calling document and principal in its return value, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site, and makes it easier for remote attackers to execute arbitrary JavaScript code by leveraging certain add-on behavior.
CVE-2020-15907 1 Mahara 1 Mahara 2020-08-12 4.3 MEDIUM 6.1 MEDIUM
In Mahara 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1, certain places could execute file or folder names containing JavaScript.
CVE-2020-17480 1 Tiny 1 Tinymce 2020-08-11 4.3 MEDIUM 6.1 MEDIUM
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
CVE-2020-16275 1 Carson-saint 1 Saint Security Suite 2020-08-11 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the Credential Manager component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link.
CVE-2020-16278 1 Carson-saint 1 Saint Security Suite 2020-08-11 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the Permissions component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link.
CVE-2020-15870 1 Sonatype 1 Nexus Repository Manager 3 2020-08-11 4.3 MEDIUM 6.1 MEDIUM
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).
CVE-2020-15869 1 Sonatype 1 Nexus Repository Manager 3 2020-08-11 4.3 MEDIUM 5.4 MEDIUM
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).
CVE-2020-17364 1 Usvn 1 User-friendly Svn 2020-08-11 4.3 MEDIUM 6.1 MEDIUM
USVN (aka User-friendly SVN) before 1.0.9 allows XSS via SVN logs.
CVE-2020-16847 1 Extremenetworks 1 Extreme Management Center 2020-08-11 4.3 MEDIUM 6.1 MEDIUM
Extreme Analytics in Extreme Management Center before 8.5.0.169 allows unauthenticated reflected XSS via a parameter in a GET request, aka CFD-4887.
CVE-2020-17476 1 Mibew 1 Messenger 2020-08-10 4.3 MEDIUM 6.1 MEDIUM
Mibew Messenger before 3.2.7 allows XSS via a crafted user name.
CVE-2020-4541 1 Ibm 1 Jazz Reporting Service 2020-08-10 4.3 MEDIUM 6.1 MEDIUM
IBM Jazz Reporting Service 7.0 and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 183039.
CVE-2020-4533 1 Ibm 1 Jazz Reporting Service 2020-08-10 4.3 MEDIUM 6.1 MEDIUM
IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182717.
CVE-2020-4539 1 Ibm 1 Jazz Reporting Service 2020-08-10 4.3 MEDIUM 6.1 MEDIUM
IBM Jazz Reporting Service 6.0.2, 6.0.6, 6.0.6.1, 7.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2020-17451 1 Flatcore 1 Flatcore 2020-08-10 3.5 LOW 4.8 MEDIUM
flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title, page_content, or page_extracontent parameter, or the acp/acp.php?tn=system&sub=sys_pref prefs_pagename, prefs_pagetitle, or prefs_pagesubtitle parameter.
CVE-2012-3992 4 Canonical, Mozilla, Redhat and 1 more 13 Ubuntu Linux, Firefox, Firefox Esr and 10 more 2020-08-10 4.3 MEDIUM N/A
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage history data, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive POST content via vectors involving a location.hash write operation and history navigation that triggers the loading of a URL into the history object.
CVE-2020-15830 1 Jetbrains 1 Teamcity 2020-08-10 4.3 MEDIUM 6.1 MEDIUM
JetBrains TeamCity before 2019.2.3 is vulnerable to stored XSS in the administration UI.
CVE-2020-15831 1 Jetbrains 1 Teamcity 2020-08-10 4.3 MEDIUM 6.1 MEDIUM
JetBrains TeamCity before 2019.2.3 is vulnerable to reflected XSS in the administration UI.
CVE-2020-11110 1 Grafana 1 Grafana 2020-08-10 4.3 MEDIUM 6.1 MEDIUM
Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.
CVE-2020-15056 1 Tp-link 2 Tl-ps310u, Tl-ps310u Firmware 2020-08-09 2.3 LOW 4.3 MEDIUM
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.
CVE-2020-15060 1 Lindy-international 2 42633, 42633 Firmware 2020-08-09 2.3 LOW 4.3 MEDIUM
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.
CVE-2020-15064 1 Digitus 2 Da-70254, Da-70254 Firmware 2020-08-09 2.3 LOW 4.3 MEDIUM
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.
CVE-2014-1530 7 Canonical, Debian, Fedoraproject and 4 more 16 Ubuntu Linux, Debian Linux, Fedora and 13 more 2020-08-07 4.3 MEDIUM 6.1 MEDIUM
The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-site scripting (XSS) attacks, via a crafted web site that performs history navigation.
CVE-2012-3994 4 Canonical, Mozilla, Redhat and 1 more 13 Ubuntu Linux, Firefox, Firefox Esr and 10 more 2020-08-07 4.3 MEDIUM N/A
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allow remote attackers to conduct cross-site scripting (XSS) attacks via a binary plugin that uses Object.defineProperty to shadow the top object, and leverages the relationship between top.location and the location property.
CVE-2020-9036 1 Jeedom 1 Jeedom 2020-08-07 4.3 MEDIUM 6.1 MEDIUM
Jeedom through 4.0.38 allows XSS.
CVE-2020-13819 1 Extremenetworks 1 Extreme Management Center 2020-08-06 4.3 MEDIUM 6.1 MEDIUM
Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
CVE-2020-16192 1 Limesurvey 1 Limesurvey 2020-08-06 4.3 MEDIUM 6.1 MEDIUM
LimeSurvey 4.3.2 allows reflected XSS because application/controllers/LSBaseController.php lacks code to validate parameters.
CVE-2012-5841 5 Canonical, Mozilla, Opensuse and 2 more 14 Ubuntu Linux, Firefox, Firefox Esr and 11 more 2020-08-06 4.3 MEDIUM N/A
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 implement cross-origin wrappers with a filtering behavior that does not properly restrict write actions, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.
CVE-2010-2301 3 Google, Opensuse, Suse 4 Chrome, Opensuse, Suse Linux Enterprise Desktop and 1 more 2020-08-06 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to inject arbitrary web script or HTML via vectors related to the node.innerHTML property of a TEXTAREA element. NOTE: this might overlap CVE-2010-1762.
CVE-2020-15944 1 Gantt-chart Project 1 Gantt-chart 2020-08-06 3.5 LOW 5.4 MEDIUM
An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is vulnerable to a persistent XSS attack. An attacker can embed the attack vectors in the dashboard of other users. To exploit this vulnerability, an attacker has to be authenticated.
CVE-2020-4525 1 Ibm 2 Engineering Workflow Management, Rational Rhapsody Design Manager 2020-08-06 3.5 LOW 5.4 MEDIUM
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182435.
CVE-2020-10643 1 Osisoft 1 Pi Vision 2020-08-05 3.5 LOW 5.4 MEDIUM
An authenticated remote attacker could use specially crafted URLs to send a victim using PI Vision 2019 mobile to a vulnerable web page due to a known issue in a third-party component.
CVE-2020-10614 1 Osisoft 1 Pi Vision 2020-08-05 3.5 LOW 4.8 MEDIUM
In OSIsoft PI System multiple products and versions, an authenticated remote attacker with write access to PI Vision databases could inject code into a display. Unauthorized information disclosure, deletion, or modification is possible if a victim views the infected display.
CVE-2020-4396 1 Ibm 1 Engineering Test Management 2020-08-05 3.5 LOW 5.4 MEDIUM
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 179359.
CVE-2020-4542 1 Ibm 1 Engineering Requirements Management Doors Next 2020-08-05 3.5 LOW 5.4 MEDIUM
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 183046.
CVE-2020-3460 1 Cisco 1 Data Center Network Manager 2020-08-05 4.3 MEDIUM 6.1 MEDIUM
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by intercepting a request from a user and injecting malicious data into an HTTP header. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.
CVE-2020-11584 2 Linux, Plesk 2 Linux Kernel, Onyx 2020-08-04 4.3 MEDIUM 6.1 MEDIUM
A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.
CVE-2020-11583 2 Microsoft, Plesk 2 Windows, Obsidian 2020-08-04 4.3 MEDIUM 6.1 MEDIUM
A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.
CVE-2020-16131 1 Tiki 1 Tiki 2020-08-04 4.3 MEDIUM 6.1 MEDIUM
Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.
CVE-2020-13820 1 Extremenetworks 1 Extreme Management Center 2020-08-04 4.3 MEDIUM 6.1 MEDIUM
Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
CVE-2020-4560 1 Ibm 1 Financial Transaction Manager 2020-08-04 4.3 MEDIUM 6.1 MEDIUM
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.