Vulnerabilities (CVE)

Filtered by CWE-79
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-8957 1 Covercms Project 1 Covercms 2018-04-18 3.5 LOW 5.4 MEDIUM
CoverCMS v1.1.6 has XSS via the fourth input box to index.php, related to admina/mconfigs.inc.php.
CVE-2018-8942 1 Xiuno Bbs Project 1 Xiuno Bbs 2018-04-18 3.5 LOW 5.4 MEDIUM
Xiuno BBS 4.0.0 has XSS in the adminpage sitename parameter.
CVE-2018-8903 1 Open-audit 1 Open-audit 2018-04-18 3.5 LOW 5.4 MEDIUM
Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.
CVE-2018-8906 1 Dsmall Project 1 Dsmall 2018-04-18 4.3 MEDIUM 6.1 MEDIUM
dsmall v20180320 has XSS via a crafted street address to public/index.php/home/memberaddress/index.html, which is mishandled at public/index.php/home/memberaddress/edit/address_id/2.html.
CVE-2018-8899 1 Identityserver 1 Identityserver4 2018-04-18 4.3 MEDIUM 6.1 MEDIUM
IdentityServer IdentityServer4 1.x before 1.5.3 and 2.x before 2.1.3 does not encode the redirect URI on the authorization response page, which might lead to XSS in some configurations.
CVE-2017-18094 1 Atlassian 2 Crucible, Fisheye 2018-04-18 3.5 LOW 4.8 MEDIUM
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the base path setting of a configured file system repository.
CVE-2018-9017 1 Dsmall Project 1 Dsmall 2018-04-18 3.5 LOW 5.4 MEDIUM
dsmall v20180320 allows XSS via the member search box at the public/index.php/home/membersnsfriend/findlist.html URI.
CVE-2018-9016 1 Dsmall Project 1 Dsmall 2018-04-18 4.3 MEDIUM 6.1 MEDIUM
dsmall v20180320 allows XSS via the main page search box at the public/index.php/home URI.
CVE-2018-9307 1 Dsmall Project 1 Dsmall 2018-04-18 4.3 MEDIUM 6.1 MEDIUM
dsmall v20180320 allows XSS via the pdr_sn parameter to public/index.php/home/predeposit/index.html.
CVE-2018-9015 1 Dsmall Project 1 Dsmall 2018-04-18 3.5 LOW 5.4 MEDIUM
dsmall v20180320 allows XSS via the public/index.php/home/predeposit/index.html pdr_sn parameter (aka the CMS search box).
CVE-2018-9121 1 Crea8social 1 Crea8social 2018-04-18 3.5 LOW 5.4 MEDIUM
In Crea8social 2018.2, there is Stored Cross-Site Scripting via a post comment.
CVE-2018-9122 1 Crea8social 1 Crea8social 2018-04-18 3.5 LOW 5.4 MEDIUM
In Crea8social 2018.2, there is Reflected Cross-Site Scripting via the term parameter to the /search URI.
CVE-2018-9123 1 Crea8social 1 Crea8social 2018-04-18 3.5 LOW 5.4 MEDIUM
In Crea8social 2018.2, there is Stored Cross-Site Scripting via a User Profile.
CVE-2018-9120 1 Crea8social 1 Crea8social 2018-04-18 3.5 LOW 5.4 MEDIUM
In Crea8social 2018.2, there is Stored Cross-Site Scripting via a post.
CVE-2018-7196 1 Osticket 1 Osticket 2018-04-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" parameter.
CVE-2018-7193 1 Osticket 1 Osticket 2018-04-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "order" parameter.
CVE-2018-7192 1 Osticket 1 Osticket 2018-04-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "message" parameter.
CVE-2018-9925 1 Icmsdev 1 Icms 2018-04-17 3.5 LOW 5.4 MEDIUM
An issue was discovered in idreamsoft iCMS through 7.0.7. XSS exists via the nickname field in an admincp.php?app=user&do=save&frame=iPHP request.
CVE-2018-8832 1 Enhavo 1 Enhavo 2018-04-17 3.5 LOW 4.8 MEDIUM
enhavo 0.4.0 has XSS via a user-group that contains executable JavaScript code in the user-group name. The XSS attack launches when a victim visits the admin user group page.
CVE-2018-5233 1 Getgrav 1 Grav Cms 2018-04-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/tools.
CVE-2018-0538 1 Qqq Systems Project 1 Qqq Systems 2018-04-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-0534 1 Arsenol Project 1 Arsenol 2018-04-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in ArsenoL Version 0.5 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-10033 1 Cmsmadesimple 1 Cms Made Simple 2018-04-13 3.5 LOW 4.8 MEDIUM
CMS Made Simple (aka CMSMS) 2.2.7 has Stored XSS in admin/siteprefs.php via the metadata parameter.
CVE-2018-10029 1 Cmsmadesimple 1 Cms Made Simple 2018-04-13 3.5 LOW 4.8 MEDIUM
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_name parameter, related to moduledepends, a different vulnerability than CVE-2017-16799.
CVE-2018-10032 1 Cmsmadesimple 1 Cms Made Simple 2018-04-13 3.5 LOW 4.8 MEDIUM
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter.
CVE-2018-8737 1 Bylancer 1 Bookme 2018-04-13 3.5 LOW 5.4 MEDIUM
Bookme Control Panel 2.0 Application is vulnerable to stored XSS within the Customers "Book Me" function. Within the Name and Note (aka custName and custNote) sections of the Customers screen, the application does not sanitize user-supplied input and renders injected JavaScript code to the user's browser.
CVE-2018-8948 1 Misp-project 1 Misp 2018-04-13 4.3 MEDIUM 6.1 MEDIUM
In MISP before 2.4.89, app/View/Events/resolved_attributes.ctp has multiple XSS issues via a malicious MISP module.
CVE-2018-0535 1 Php 2chbbs Project 1 Php 2chbbs 2018-04-13 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in PHP 2chBBS version bbs18c allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-8805 1 Yxcms 1 Yxcms 2018-04-13 4.3 MEDIUM 6.1 MEDIUM
Yxcms building system (compatible cell phone) v1.4.7 has XSS via the content parameter to protected\apps\default\view\default\extend_guestbook.php or protected\apps\default\view\mobile\extend_guestbook.php in an index.php?r=default/column/index&col=guestbook request.
CVE-2018-8815 1 Alkacon 1 Opencms 2018-04-13 3.5 LOW 4.6 MEDIUM
Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to inject arbitrary web script or HTML via a malicious SVG image.
CVE-2014-1665 1 Owncloud 1 Owncloud 2018-04-13 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.
CVE-2018-8767 1 Joyplus-cms Project 1 Joyplus-cms 2018-04-13 3.5 LOW 4.8 MEDIUM
joyplus-cms 1.6.0 has XSS in manager/admin_ajax.php?action=save&tab={pre}vod_type via the t_name parameter.
CVE-2018-1000139 1 I-librarian 1 I Librarian 2018-04-13 4.3 MEDIUM 6.1 MEDIUM
I, Librarian version 4.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in "id" parameter in stable.php that can result in an attacker using the XSS to send a malicious script to an unsuspecting user.
CVE-2017-17958 1 Php Multivendor Ecommerce Project 1 Php Multivendor Ecommerce 2018-04-13 4.3 MEDIUM 6.1 MEDIUM
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter.
CVE-2017-17955 1 Php Multivendor Ecommerce Project 1 Php Multivendor Ecommerce 2018-04-13 4.3 MEDIUM 6.1 MEDIUM
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the shopping-cart.php cusid parameter.
CVE-2017-17956 1 Php Multivendor Ecommerce Project 1 Php Multivendor Ecommerce 2018-04-13 4.3 MEDIUM 6.1 MEDIUM
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter.
CVE-2017-17954 1 Php Multivendor Ecommerce Project 1 Php Multivendor Ecommerce 2018-04-13 4.3 MEDIUM 6.1 MEDIUM
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the seller-view.php usid parameter.
CVE-2017-17953 1 Php Multivendor Ecommerce Project 1 Php Multivendor Ecommerce 2018-04-13 4.3 MEDIUM 6.1 MEDIUM
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter.
CVE-2017-17949 1 Cells 1 Blog 2018-04-13 4.3 MEDIUM 6.1 MEDIUM
Cells Blog 3.5 has XSS via the pub_readpost.php fmid parameter.
CVE-2017-17948 1 Cells 1 Blog 2018-04-13 4.3 MEDIUM 6.1 MEDIUM
Cells Blog 3.5 has XSS via the jfdname parameter in an act=showpic request.
CVE-2018-0536 1 Qqq Systems Project 1 Qqq Systems 2018-04-12 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via quiz.cgi.
CVE-2018-0537 1 Qqq Systems Project 1 Qqq Systems 2018-04-12 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in QQQ SYSTEMS ver2.24 allows an attacker to inject arbitrary web script or HTML via quiz_op.cgi.
CVE-2015-7458 1 Ibm 1 Connections 2018-04-12 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108354.
CVE-2015-7460 1 Ibm 1 Connections 2018-04-12 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108356.
CVE-2015-7459 1 Ibm 1 Connections 2018-04-12 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108355.
CVE-2018-8732 1 Wampserver 1 Wampserver 2018-04-12 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_del parameter.
CVE-2018-6842 1 Kentico 1 Kentico Cms 2018-04-12 3.5 LOW 5.4 MEDIUM
Kentico 10 before 10.0.50 and 11 before 11.0.3 has XSS in which a crafted URL results in improper construction of a system page.
CVE-2017-17442 1 Blackberry 1 Unified Endpoint Manager 2018-04-11 4.3 MEDIUM 6.1 MEDIUM
In BlackBerry UEM Management Console version 12.7.1 and earlier, a reflected cross-site scripting vulnerability that could allow an attacker to execute script commands in the context of the affected UEM Management Console account by crafting a malicious link and then persuading a user with legitimate access to the Management Console to click on the malicious link.
CVE-2018-7563 1 Glpi-project 1 Glpi 2018-04-11 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute JavaScript code supplied by the attacker. The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.
CVE-2018-8728 1 Kontena 1 Kontena 2018-04-11 4.3 MEDIUM 6.1 MEDIUM
server/app/views/static/code.html in Kontena before 1.5.0 allows XSS in "kontena master login --remote" code display, as demonstrated by /code#code= in a URI.