Vulnerabilities (CVE)

Filtered by CWE-79
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-0255 1 Ibm 1 Marketing Platform 2017-05-12 4.3 MEDIUM 6.1 MEDIUM
IBM Marketing Platform 9.1 and 10.0 is vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 110564.
CVE-2017-8762 1 Genixcms 1 Genixcms 2017-05-12 3.5 LOW 5.4 MEDIUM
GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element.
CVE-2017-8780 1 Genixcms 1 Genixcms 2017-05-12 3.5 LOW 4.8 MEDIUM
GeniXCMS 1.0.2 has XSS triggered by a comment that is mishandled during a publish operation by an administrator, as demonstrated by a malformed P element.
CVE-2017-8384 1 Craftcms 1 Craft Cms 2017-05-11 4.3 MEDIUM 6.1 MEDIUM
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
CVE-2017-8376 1 Genixcms 1 Genixcms 2017-05-10 3.5 LOW 5.4 MEDIUM
GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.
CVE-2017-8302 1 Blueriver 1 Muracms 2017-05-10 3.5 LOW 5.4 MEDIUM
Mura CMS 7.0.6967 allows admin/?muraAction= XSS attacks, related to admin/core/views/carch/list.cfm, admin/core/views/carch/loadsiteflat.cfm, admin/core/views/cusers/inc/dsp_nextn.cfm, admin/core/views/cusers/inc/dsp_search_form.cfm, admin/core/views/cusers/inc/dsp_users_list.cfm, admin/core/views/cusers/list.cfm, and admin/core/views/cusers/listusers.cfm.
CVE-2017-2106 1 Webmin 1 Webmin 2017-05-10 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting vulnerabilities in Webmin versions prior to 1.830 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-7271 1 Yii Software 1 Yii 2017-05-08 4.3 MEDIUM 6.1 MEDIUM
Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen.
CVE-2017-2148 1 Iodata 2 Wn-ac1167gr, Wn-ac1167gr Firmware 2017-05-05 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in WN-AC1167GR firmware version 1.04 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-2151 1 Booking Calendar Project 1 Booking Calendar 2017-05-05 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-2136 1 Wp Statistics 1 Wp Statistics 2017-05-05 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
CVE-2017-2127 1 Yourownprogrammer 1 Yop Poll 2017-05-05 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in YOP Poll versions prior to 5.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-7841 1 Olive Design 1 Olive Diary Dx 2017-05-05 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Olive Diary DX allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CVE-2016-7839 1 Olive Design 1 Olive Blog 2017-05-05 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Olive Blog allows remote attackers to inject arbitrary web script or HTML via the search parameter.
CVE-2017-2123 1 Onethird 1 Onethird Cms 2017-05-05 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in OneThird CMS v1.73 Heaven's Door and earlier allows remote attackers to inject arbitrary web script or HTML via language.php.
CVE-2017-2114 1 Cybozu 1 Office 2017-05-03 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-8298 1 Cnvs 1 Canvas 2017-05-03 3.5 LOW 5.4 MEDIUM
cnvs.io Canvas 3.3.0 has XSS in the title and content fields of a "Posts > Add New" action, and during creation of new tags and users.
CVE-2017-7987 1 Joomla 1 Joomla\! 2017-05-03 4.3 MEDIUM 6.1 MEDIUM
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.
CVE-2016-8924 1 Ibm 1 Maximo Asset Management 2017-05-03 4.3 MEDIUM 5.6 MEDIUM
IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 118537.
CVE-2017-2092 1 Cybozu 1 Garoon 2017-05-03 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-5191 1 Netiq 1 Access Manager 2017-05-03 4.3 MEDIUM 6.1 MEDIUM
An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.
CVE-2017-7986 1 Joomla 1 Joomla\! 2017-05-02 4.3 MEDIUM 6.1 MEDIUM
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.
CVE-2017-2118 1 Wbce 1 Wbce Cms 2017-05-02 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-7984 1 Joomla 1 Joomla\! 2017-05-02 4.3 MEDIUM 6.1 MEDIUM
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component.
CVE-2017-7386 1 Symetrie Project 1 Symetrie 2017-05-02 4.3 MEDIUM 6.1 MEDIUM
citymont/symetrie v.0.9.6 is vulnerable to a reflected XSS in symetrie-master/app/commands/page.php (model parameter).
CVE-2016-9723 1 Ibm 2 Qradar Incident Forensics, Qradar Security Information And Event Manager 2017-05-02 4.3 MEDIUM 6.1 MEDIUM
IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999534.
CVE-2017-7590 1 Openidm Project 1 Openidm 2017-04-29 4.3 MEDIUM 6.1 MEDIUM
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to persistent cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by a crafted Managed Object Name.
CVE-2016-6333 1 Mediawiki 1 Mediawiki 2017-04-29 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the CSS user subpage preview feature in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via the edit box in Special:MyPage/common.css.
CVE-2016-6334 1 Mediawiki 1 Mediawiki 2017-04-29 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the Parser::replaceInternalLinks2 method in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving replacement of percent encoding in unclosed internal links.
CVE-2017-8085 1 Exponentcms 1 Exponent Cms 2017-04-29 4.3 MEDIUM 6.1 MEDIUM
In Exponent CMS before 2.4.1 Patch #5, XSS in elFinder is possible in framework/modules/file/connector/elfinder.php.
CVE-2017-8102 1 S9y 1 Serendipity 2017-04-28 3.5 LOW 5.4 MEDIUM
Stored XSS in Serendipity v2.1-rc1 allows an attacker to steal an admin's cookie and other information by composing a new entry as an editor user. This is related to lack of the serendipity_event_xsstrust plugin and a set_config error in that plugin.
CVE-2017-7944 1 Xoops 1 Xoops 2017-04-27 4.3 MEDIUM 6.1 MEDIUM
XOOPS Core 2.5.8.1 has XSS due to unescaped HTML output of an Install DB failure error message in page_dbsettings.php.
CVE-2017-8103 1 Mybb 1 Mybb 2017-04-27 4.3 MEDIUM 6.1 MEDIUM
In MyBB before 1.8.11, the Email MyCode component allows XSS, as demonstrated by an onmouseover event.
CVE-2017-7992 1 Heartland Payment Systems 1 Heartland-php 2017-04-27 4.3 MEDIUM 6.1 MEDIUM
Heartland Payment Systems Payment Gateway PHP SDK hps/heartland-php v2.8.17 is vulnerable to a reflected XSS in examples/consumer-authentication/cruise.php via the URI, as demonstrated by the cavv parameter.
CVE-2016-9980 1 Ibm 1 Curam Social Program Management 2017-04-27 3.5 LOW 5.4 MEDIUM
IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120256.
CVE-2016-9979 1 Ibm 1 Curam Social Program Management 2017-04-27 3.5 LOW 5.4 MEDIUM
IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120255.
CVE-2017-8052 1 Craftcms 1 Craft Cms 2017-04-26 4.3 MEDIUM 6.1 MEDIUM
Craft CMS before 2.6.2974 allows XSS attacks.
CVE-2017-5183 1 Netiq 1 Access Manager 2017-04-26 4.3 MEDIUM 6.1 MEDIUM
NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document.
CVE-2016-4849 1 Geeklog Project 1 Geeklog 2017-04-25 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog IVYWE edition 2.1.1 allow remote attackers to inject arbitrary web script or HTML by leveraging use of the COM_getCurrentURL function in (1) public_html/layout/default/header.thtml, (2) public_html/layout/bento/header.thtml, (3) public_html/layout/fotos/header.thtml, or (4) public_html/layout/default/article/article.thtml.
CVE-2016-4847 1 Ossec 1 Web Ui 2017-04-25 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web script or HTML by leveraging an unanchored regex.
CVE-2016-6347 1 Redhat 1 Resteasy 2017-04-25 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-7891 1 Sourcebans-pp Project 1 Sourcebans-pp 2017-04-25 4.3 MEDIUM 6.1 MEDIUM
sourcebans-pp (SourceBans++) 1.5.4.7 has XSS in admin.comms.php via the rebanid parameter.
CVE-2016-1217 1 Cybozu 1 Garoon 2017-04-25 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the "Check available times" function in Cybozu Garoon before 4.2.2.
CVE-2016-1214 1 Cybozu 1 Garoon 2017-04-25 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the "Response request" function in Cybozu Garoon before 4.2.2.
CVE-2016-1215 1 Cybozu 1 Garoon 2017-04-25 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the "User details" function in Cybozu Garoon before 4.2.2.
CVE-2016-1216 1 Cybozu 1 Garoon 2017-04-25 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the "New appointment" function in Cybozu Garoon before 4.2.2.
CVE-2017-7896 1 Trendmicro 1 Interscan Messaging Security Virtual Appliance 2017-04-25 4.3 MEDIUM 6.1 MEDIUM
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS.
CVE-2017-7871 1 Tdm Project 1 Tdm 2017-04-25 4.3 MEDIUM 6.1 MEDIUM
trollepierre/tdm before 2017-04-13 is vulnerable to a reflected XSS in tdm-master/webhook.php (challenge parameter).
CVE-2015-8256 1 Axis 11 Cannon Network Camera, Explosion-protected Camera, Fixed Box Camera and 8 more 2017-04-25 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
CVE-2017-1160 1 Ibm 1 Financial Transaction Manager 2017-04-25 3.5 LOW 5.4 MEDIUM
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 122892.