Vulnerabilities (CVE)

Filtered by CWE-79
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-0654 1 Weseek 1 Growi 2018-09-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the modal for creating Wiki page.
CVE-2018-0653 1 Weseek 1 Growi 2018-09-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via Wiki page view.
CVE-2018-0652 1 Weseek 1 Growi 2018-09-21 3.5 LOW 4.8 MEDIUM
Cross-site scripting vulnerability in GROWI v.3.1.11 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via the UserGroup Management section of admin page.
CVE-2018-14430 1 Mondula 1 Multi Step Form 2018-09-20 4.3 MEDIUM 6.1 MEDIUM
The Mondula Multi Step Form plugin through 1.2.5 for WordPress allows XSS via the fw_data [id][1], fw_data [id][2], fw_data [id][3], fw_data [id][4], or email field of the contact form, exploitable with an fw_send_email action to wp-admin/admin-ajax.php.
CVE-2018-1999016 1 Pydio 1 Pydio 2018-09-19 4.3 MEDIUM 6.1 MEDIUM
Pydio version 8.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in ./core/vendor/meenie/javascript-packer/example-inline.php line 48; ./core/vendor/dapphp/securimage/examples/test.mysql.static.php lines: 114,118 that can result in an unauthenticated remote attacker manipulating the web client via XSS code injection. This attack appear to be exploitable via the victim openning a specially crafted URL. This vulnerability appears to have been fixed in version 8.2.1.
CVE-2018-1999024 1 Mathjax 1 Mathjax 2018-09-19 4.3 MEDIUM 5.4 MEDIUM
MathJax version prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability in the \unicode{} macro that can result in Potentially untrusted Javascript running within a web browser. This attack appear to be exploitable via The victim must view a page where untrusted content is processed using Mathjax. This vulnerability appears to have been fixed in 2.7.4 and later.
CVE-2018-1999021 1 Gleeztech 1 Gleezcms 2018-09-19 3.5 LOW 5.4 MEDIUM
Gleezcms Gleez Cms version 1.3.0 contains a Cross Site Scripting (XSS) vulnerability in Profile page that can result in Inject arbitrary web script or HTML via the profile page editor. This attack appear to be exploitable via The victim must navigate to the attacker's profile page.
CVE-2018-14527 1 Xiao5ucompany Project 1 Xiao5ucompany 2018-09-18 4.3 MEDIUM 6.1 MEDIUM
Feedback.asp in Xiao5uCompany 1.7 has XSS because the XSS protection mechanism in Safe.asp is insufficient (for example, it considers SCRIPT and IMG elements, but does not consider VIDEO elements).
CVE-2018-14606 1 Gitlab 1 Gitlab 2018-09-18 3.5 LOW 5.4 MEDIUM
An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur via a Milestone name during a promotion.
CVE-2018-14604 1 Gitlab 1 Gitlab 2018-09-18 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the tooltip of the job inside the CI/CD pipeline.
CVE-2018-14605 1 Gitlab 1 Gitlab 2018-09-18 3.5 LOW 5.4 MEDIUM
An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. XSS can occur in the branch name during a Web IDE file commit.
CVE-2017-18343 1 Sensiolabs 1 Symfony 2018-09-18 4.3 MEDIUM 6.1 MEDIUM
** DISPUTED ** The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: the vendor's position is that this is not a vulnerability because the debug tools are not intended for production use. NOTE: the Symfony Debug component is used by Laravel Debugbar.
CVE-2018-1529 1 Ibm 2 Rational Doors Next Generation, Rational Requirements Composer 2018-09-18 3.5 LOW 5.4 MEDIUM
IBM Rational DOORS Next Generation 5.0 through 5.0.2, 6.0 through 6.0.5 and IBM Rational Requirements Composer 5.0 through 5.0.2 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142291.
CVE-2018-14415 1 Icmsdev 1 Icms 2018-09-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen.
CVE-2018-5232 1 Atlassian 1 Jira 2018-09-17 4.3 MEDIUM 6.1 MEDIUM
The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.10.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuetype parameter.
CVE-2018-14422 1 Sanscms 1 Sanscms 2018-09-17 4.3 MEDIUM 6.1 MEDIUM
blog/index.php in SansCMS 0.7 has XSS via the q parameter.
CVE-2018-13387 1 Atlassian 1 Jira 2018-09-17 4.3 MEDIUM 6.1 MEDIUM
The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3 and from version 7.10.0 before version 7.10.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter as the fix for CVE-2017-18039 was incomplete.
CVE-2018-14380 1 Graylog 1 Graylog 2018-09-14 4.3 MEDIUM 6.1 MEDIUM
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
CVE-2018-12429 1 Jeesns 1 Jeesns 2018-09-14 3.5 LOW 5.4 MEDIUM
JEESNS through 1.2.1 allows XSS attacks by ordinary users who publish articles containing a crafted payload in order to capture an administrator cookie.
CVE-2018-14082 1 Freelancewebdesignerchennai 1 Job Portal 2018-09-14 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall JOB SITE (aka Job Portal) 3.0.1 has Cross-site Scripting (XSS) via the search bar.
CVE-2018-14513 1 Wuzhi Cms Project 1 Wuzhi Cms 2018-09-14 4.3 MEDIUM 6.1 MEDIUM
An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[content] parameter to the index.php?m=feedback&f=index&v=contact URI.
CVE-2018-14517 1 Seacms 1 Seacms 2018-09-14 4.3 MEDIUM 6.1 MEDIUM
SeaCMS 6.61 has two XSS issues in the admin_config.php file via certain form fields.
CVE-2018-14419 1 Metinfo 1 Metinfo 2018-09-14 3.5 LOW 4.8 MEDIUM
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.
CVE-2018-14392 1 Mybb 1 New Threads 2018-09-13 4.3 MEDIUM 6.1 MEDIUM
The New Threads plugin before 1.2 for MyBB has XSS.
CVE-2018-13832 1 Techotronic 1 All In One Favicon 2018-09-13 3.5 LOW 4.8 MEDIUM
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via Apple-Text, GIF-Text, ICO-Text, PNG-Text, or JPG-Text.
CVE-2017-17541 1 Fortinet 2 Fortianalyzer Firmware, Fortimanager Firmware 2018-09-12 4.3 MEDIUM 6.1 MEDIUM
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.
CVE-2018-5229 1 Atlassian 1 Universal Plugin Manager 2018-09-12 3.5 LOW 5.4 MEDIUM
The NotificationRepresentationFactoryImpl class in Atlassian Universal Plugin Manager before version 2.22.9 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of user submitted add-on names.
CVE-2018-14388 1 Joyplus-cms Project 1 Joyplus-cms 2018-09-12 3.5 LOW 5.4 MEDIUM
joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter.
CVE-2018-14382 1 Instantcms 1 Instantcms 2018-09-12 4.3 MEDIUM 6.1 MEDIUM
InstantCMS 2.10.1 has /redirect?url= XSS.
CVE-2018-13865 1 Idreamsoft 1 Icms 2018-09-06 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in idreamsoft iCMS 7.0.9. XSS exists via the callback parameter in a public/api.php uploadpic request, bypassing the iWAF protection mechanism.
CVE-2018-1000611 1 Openconext 1 Openconext Engineblock 2018-09-06 4.3 MEDIUM 6.1 MEDIUM
SURFnet OpenConext EngineBlock version 5.7.0 to 5.7.3 contains a Cross Site Scripting (XSS) vulnerability that can result in Allows an attacker to inject arbitrary web scripts or HTML into help and login pages. This attack appear to be exploitable via the victim opening a specially crafted URL.
CVE-2018-3747 1 Public.js Project 1 Public.js 2018-09-06 4.3 MEDIUM 6.1 MEDIUM
The public node module versions <= 1.0.3 allows to embed HTML in file names, which (in certain conditions) might lead to execute malicious JavaScript.
CVE-2018-2431 1 Sap 1 Businessobjects Business Intelligence 2018-09-06 4.3 MEDIUM 6.1 MEDIUM
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-11350 1 Jirafeau 1 Jirafeau 2018-09-05 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Jirafeau before 3.4.1. The file "search by name" form is affected by one Cross-Site Scripting vulnerability via the name parameter.
CVE-2018-13252 1 Entrustdatacard 1 Syntera Customization Suite 2018-09-05 4.3 MEDIUM 6.1 MEDIUM
Entrust Datacard Syntera CS 5.x has XSS via the name field of "Domain or Computer Name" in the login page.
CVE-2018-13878 1 Rocket.chat 1 Rocket.chat 2018-09-05 4.3 MEDIUM 6.1 MEDIUM
An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a username is displayed unescaped when the user is mentioned (using the @ symbol) in a channel or private chat. Consequently, it is possible to exfiltrate the secret token of every user and also admins in the channel.
CVE-2018-13879 1 Rocket.chat 1 Rocket.chat 2018-09-05 3.5 LOW 5.4 MEDIUM
A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, the next step will ask for a username. This field will not save HTML control characters but an error will be displayed that shows the attempted username unescaped via packages/rocketchat-ui-login/client/username/username.js in packages/rocketchat-ui-login/client/username/username.html.
CVE-2018-2435 1 Sap 1 Netweaver Enterprise Portal 2018-09-05 4.3 MEDIUM 6.1 MEDIUM
SAP NetWeaver Enterprise Portal from 7.0 to 7.02, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
CVE-2018-13849 1 Instagram-clone Project 1 Instagram-clone 2018-09-05 4.3 MEDIUM 6.1 MEDIUM
edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequate XSS protection mechanism based on preg_replace.
CVE-2017-16710 1 Crestron 4 Airmedia Am-100, Airmedia Am-100 Firmware, Airmedia Am-101 and 1 more 2018-09-05 3.5 LOW 4.8 MEDIUM
Cross-site scripting (XSS) vulnerability in Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-8299 1 Microsoft 2 Sharepoint Enterprise Server, Sharepoint Foundation 2018-09-05 3.5 LOW 5.4 MEDIUM
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8323.
CVE-2018-8323 1 Microsoft 1 Sharepoint Enterprise Server 2018-09-05 3.5 LOW 5.4 MEDIUM
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8299.
CVE-2018-8326 1 Microsoft 1 Web Customizations 2018-09-05 3.5 LOW 5.4 MEDIUM
A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Open Source Customization for Active Directory Federation Services XSS Vulnerability." This affects Web Customizations.
CVE-2018-13998 1 Clippercms 1 Clippercms 2018-09-04 3.5 LOW 4.8 MEDIUM
ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users.
CVE-2018-13999 1 Catfish-cms 1 Catfish Cms 2018-09-04 3.5 LOW 4.8 MEDIUM
Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administrator).
CVE-2018-10231 1 Topdesk 1 Topdesk 2018-09-04 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
CVE-2018-8046 1 Sencha 1 Ext Js 2018-09-04 4.3 MEDIUM 6.1 MEDIUM
The getTip() method of Action Columns of Sencha Ext JS 4 to 6 before 6.6.0 is vulnerable to XSS attacks, even when passed HTML-escaped data. This framework brings no built-in XSS protection, so the developer has to ensure that data is correctly sanitized. However, the getTip() method of Action Columns takes HTML-escaped data and un-escapes it. If the tooltip contains user-controlled data, an attacker could exploit this to create a cross-site scripting attack, even when developers took precautions and escaped data.
CVE-2013-0592 1 Ibm 1 Inotes 2018-09-04 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 83815.
CVE-2018-13388 1 Atlassian 2 Crucible, Fisheye 2018-09-04 3.5 LOW 5.4 MEDIUM
The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in attached files.
CVE-2018-11124 1 Opmantek 1 Open-audit 2018-09-02 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted attribute name of an Attribute.