Vulnerabilities (CVE)

Filtered by CWE-79
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-13758 1 Bitrix 1 Bitrix24 2020-06-02 4.3 MEDIUM 6.1 MEDIUM
modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by placing %00 before the payload.
CVE-2020-8035 1 Horde 1 Groupware 2020-06-01 4.3 MEDIUM 6.1 MEDIUM
The image view functionality in Horde Groupware Webmail Edition before 5.2.22 is affected by a stored Cross-Site Scripting (XSS) vulnerability via an SVG image upload containing a JavaScript payload. An attacker can obtain access to a victim's webmail account by making them visit a malicious URL.
CVE-2020-8034 1 Horde 2 Gollem, Groupware 2020-05-31 4.3 MEDIUM 6.1 MEDIUM
Gollem before 3.0.13, as used in Horde Groupware Webmail Edition 5.2.22 and other products, is affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the browser functionality, affecting breadcrumb output. An attacker can obtain access to a victim's webmail account by making them visit a malicious URL.
CVE-2018-18405 1 Jquery 1 Jquery 2020-05-31 4.3 MEDIUM 6.1 MEDIUM
** DISPUTED ** jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry.
CVE-2017-1000427 1 Marked Project 1 Marked 2020-05-31 4.3 MEDIUM 6.1 MEDIUM
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
CVE-2020-4306 1 Ibm 1 Planning Analytics Local 2020-05-29 3.5 LOW 5.4 MEDIUM
IBM Planning Analytics Local 2.0.0 through 2.0.9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176735.
CVE-2020-4419 1 Ibm 1 Jazz Reporting Service 2020-05-29 3.5 LOW 5.4 MEDIUM
IBM Jazz Reporting Service 6.0.6, 6.0.6.1, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180071.
CVE-2020-13660 1 Cmsmadesimple 1 Cms Made Simple 2020-05-29 3.5 LOW 4.8 MEDIUM
CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name.
CVE-2020-13644 1 Pickplugins 1 Accordion 2020-05-28 3.5 LOW 5.4 MEDIUM
An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax_import_json action allowed any authenticated user with Subscriber or higher permissions the ability to import a new accordion and inject malicious JavaScript as part of the accordion.
CVE-2020-8170 1 Ui 51 Ag-hp-2g16, Ag-hp-2g20, Ag-hp-5g23 and 48 more 2020-05-28 4.3 MEDIUM 6.1 MEDIUM
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:Multiple end-points with parameters vulnerable to reflected cross site scripting (XSS), allowing attackers to abuse the user' session information and/or account takeover of the admin user.Mitigation:Update to the latest AirMax AirOS firmware version available at the AirMax download page.
CVE-2017-8876 1 Getsymphony 1 Symphony 2020-05-28 4.3 MEDIUM 6.1 MEDIUM
Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php.
CVE-2020-13487 1 Bbpress 1 Bbpress 2020-05-28 3.5 LOW 4.8 MEDIUM
The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI.
CVE-2015-1864 1 Kallithea-scm 1 Kallithea 2020-05-28 3.5 LOW 5.4 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name user details, or the (3) repository, (4) repository group, or (5) user group description.
CVE-2020-13628 1 Centreon 3 Centreon Host-monitoring Widget, Centreon Service-monitoring Widget, Centreon Tactical-overview Widget 2020-05-28 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to host-monitoring/src/toolbar.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.
CVE-2020-10946 1 Centreon 3 Centreon Host-monitoring Widget, Centreon Service-monitoring Widget, Centreon Tactical-overview Widget 2020-05-28 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the page parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.
CVE-2020-13627 1 Centreon 3 Centreon Host-monitoring Widget, Centreon Service-monitoring Widget, Centreon Tactical-overview Widget 2020-05-28 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to service-monitoring/src/index.php. This vulnerability is fixed in versions 1.6.4, 18.10.3, 19.04.3, and 19.0.1 of the Centreon host-monitoring widget; 1.6.4, 18.10.5, 19.04.3, 19.10.2 of the Centreon service-monitoring widget; and 1.0.3, 18.10.1, 19.04.1, 19.10.1 of the Centreon tactical-overview widget.
CVE-2020-12261 1 Opmantek 1 Open-audit 2020-05-28 3.5 LOW 5.4 MEDIUM
Open-AudIT 3.3.0 allows an XSS attack after login.
CVE-2020-8603 1 Trendmicro 1 Interscan Web Security Virtual Appliance 2020-05-28 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting vulnerability (XSS) in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow a remote attacker to tamper with the web interface of affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
CVE-2020-13430 1 Grafana 1 Grafana 2020-05-28 4.3 MEDIUM 6.1 MEDIUM
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
CVE-2020-13633 1 Fork-cms 1 Fork Cms 2020-05-27 4.3 MEDIUM 6.1 MEDIUM
Fork before 5.8.3 allows XSS via navigation_title or title.
CVE-2020-4358 1 Ibm 1 Spectrum Scale 2020-05-27 3.5 LOW 5.4 MEDIUM
IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 178762.
CVE-2020-1063 1 Microsoft 1 Dynamics 365 2020-05-27 3.5 LOW 5.4 MEDIUM
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'.
CVE-2020-13459 1 Verbb 1 Image Resizer 2020-05-27 3.5 LOW 5.4 MEDIUM
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action.
CVE-2020-1055 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2020-05-26 4.3 MEDIUM 6.1 MEDIUM
A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize user inputs, aka 'Microsoft Active Directory Federation Services Cross-Site Scripting Vulnerability'.
CVE-2020-1105 1 Microsoft 2 Sharepoint Enterprise Server, Sharepoint Server 2020-05-26 3.5 LOW 5.4 MEDIUM
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1104, CVE-2020-1107.
CVE-2020-1104 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2020-05-26 3.5 LOW 5.4 MEDIUM
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1105, CVE-2020-1107.
CVE-2020-1107 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2020-05-26 3.5 LOW 5.4 MEDIUM
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1104, CVE-2020-1105.
CVE-2020-8789 1 Composr Project 1 Composr 2020-05-26 3.5 LOW 5.4 MEDIUM
Composr 10.0.30 allows Persistent XSS via a Usergroup name under the Security configuration.
CVE-2020-13429 1 Grafana 1 Piechart-panel 2020-05-26 3.5 LOW 5.4 MEDIUM
legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option.
CVE-2020-11888 1 Python-markdown2 Project 1 Python-markdown2 2020-05-25 4.3 MEDIUM 6.1 MEDIUM
python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.
CVE-2011-2342 1 Google 1 Chrome 2020-05-22 4.3 MEDIUM N/A
The DOM implementation in Google Chrome before 12.0.742.91 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
CVE-2011-1819 1 Google 1 Chrome 2020-05-22 4.3 MEDIUM N/A
Google Chrome before 12.0.742.91 allows remote attackers to perform unspecified injection into a chrome:// page via vectors related to extensions.
CVE-2020-1099 1 Microsoft 2 Sharepoint Enterprise Server, Sharepoint Server 2020-05-22 3.5 LOW 5.4 MEDIUM
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1100, CVE-2020-1101, CVE-2020-1106.
CVE-2020-1100 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2020-05-22 3.5 LOW 5.4 MEDIUM
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1101, CVE-2020-1106.
CVE-2011-1815 1 Google 1 Chrome 2020-05-22 4.3 MEDIUM N/A
Google Chrome before 12.0.742.91 allows remote attackers to inject script into a tab page via vectors related to extensions.
CVE-2020-1101 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2020-05-22 3.5 LOW 5.4 MEDIUM
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1100, CVE-2020-1106.
CVE-2020-13258 1 Contentful 1 Python Example 2020-05-21 4.3 MEDIUM 6.1 MEDIUM
Contentful through 2020-05-21 for Python allows reflected XSS, as demonstrated by the api parameter to the-example-app.py.
CVE-2020-13145 1 Edx 1 Open Edx Platform 2020-05-20 3.5 LOW 5.4 MEDIUM
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.
CVE-2020-13239 1 Dolibarr 1 Dolibarr 2020-05-20 3.5 LOW 5.4 MEDIUM
The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct download link. This causes XSS.
CVE-2020-13225 1 Phpipam 1 Phpipam 2020-05-20 3.5 LOW 4.8 MEDIUM
phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the User Instructions widget.
CVE-2020-11845 1 Microfocus 1 Service Manager 2020-05-19 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting vulnerability in Micro Focus Service Manager product. Affecting versions 9.50, 9.51, 9.52, 9.60, 9.61, 9.62, 9.63. The vulnerability could be exploited to allow remote attackers to inject arbitrary web script or HTML.
CVE-2020-6956 1 Pcs 1 Dexicon Enterprise 2020-05-19 4.3 MEDIUM 6.1 MEDIUM
PCS DEXICON 3.4.1 allows XSS via the loginName parameter in login_action.jsp.
CVE-2020-4298 1 Ibm 2 Infosphere Information Server, Infosphere Information Server On Cloud 2020-05-19 3.5 LOW 5.4 MEDIUM
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176475.
CVE-2019-20802 1 Readdle 1 Documents 2020-05-19 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server improperly displays directory names, leading to Stored XSS, which may be used to steal a user's data. This requires user interaction because there is no known direct way for an attacker to create a crafted directory name on a victim's device. However, a crafted directory name can occur if a victim extracts a ZIP archive that was provided by an attacker.
CVE-2020-13153 1 Misp 1 Misp 2020-05-19 4.3 MEDIUM 6.1 MEDIUM
app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view.
CVE-2020-12882 1 Rcos 1 Submitty 2020-05-19 3.5 LOW 5.4 MEDIUM
Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a Teaching Fellow.
CVE-2020-7809 1 Altools 1 Alsong 2020-05-19 4.3 MEDIUM 6.1 MEDIUM
ALSong 3.46 and earlier version contain a Document Object Model (DOM) based cross-site scripting vulnerability caused by improper validation of user input. A remote attacker could exploit this vulnerability by tricking the victim to open ALSong Album(sab) file.
CVE-2019-15083 1 Zohocorp 1 Manageengine Servicedesk Plus 2020-05-19 4.3 MEDIUM 6.1 MEDIUM
Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine ServiceDesk administrator side. At "Asset Home > Server > <workstation> > software" the administrator of ManageEngine can control what software is installed on the workstation. This table shows all the installed program names in the Software column. In this field, a remote attacker can inject malicious code in order to execute it when the ManageEngine administrator visualizes this page.
CVE-2020-13094 1 Dolibarr 1 Dolibarr 2020-05-19 3.5 LOW 5.4 MEDIUM
Dolibarr before 11.0.4 allows XSS.
CVE-2020-11930 1 Gtranslate 1 Translate Wordpress With Gtranslate 2020-05-19 4.3 MEDIUM 6.1 MEDIUM
The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.