Search
Total
20468 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2021-24699 | 1 Easy Media Download Project | 1 Easy Media Download | 2021-10-27 | 3.5 LOW | 5.4 MEDIUM |
| The Easy Media Download WordPress plugin before 1.1.7 does not escape the text argument of its shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. | |||||
| CVE-2021-24785 | 1 Great-quotes Project | 1 Great-quotes | 2021-10-27 | 3.5 LOW | 4.8 MEDIUM |
| The Great Quotes WordPress plugin through 1.0.0 does not sanitise and escape the Quote and Author fields of its Quotes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. | |||||
| CVE-2021-42534 | 1 Trane | 2 Tracer Sc, Tracer Sc Firmware | 2021-10-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| The affected product’s web application does not properly neutralize the input during webpage generation, which could allow an attacker to inject code in the input forms. | |||||
| CVE-2021-41169 | 1 Sulu | 1 Sulu | 2021-10-27 | 3.5 LOW | 4.8 MEDIUM |
| Sulu is an open-source PHP content management system based on the Symfony framework. In versions before 1.6.43 are subject to stored cross site scripting attacks. HTML input into Tag names is not properly sanitized. Only admin users are allowed to create tags. Users are advised to upgrade. | |||||
| CVE-2021-39221 | 1 Nextcloud | 1 Contacts | 2021-10-27 | 3.5 LOW | 5.4 MEDIUM |
| Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0.3 was vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, a user would need to right-click on a malicious file and open the file in a new tab. Due the strict Content-Security-Policy shipped with Nextcloud, this issue is not exploitable on modern browsers supporting Content-Security-Policy. It is recommended that the Nextcloud Contacts application is upgraded to 4.0.3. As a workaround, one may use a browser that has support for Content-Security-Policy. | |||||
| CVE-2021-31373 | 1 Juniper | 28 Junos, Srx100, Srx110 and 25 more | 2021-10-27 | 3.5 LOW | 5.4 MEDIUM |
| A persistent Cross-Site Scripting (XSS) vulnerability in Juniper Networks Junos OS on SRX Series, J-Web interface may allow a remote authenticated user to inject persistent and malicious scripts. An attacker can exploit this vulnerability to steal sensitive data and credentials from a web administration session, or hijack another user's active session to perform administrative actions. This issue affects: Juniper Networks Junos OS on SRX Series: 18.2 versions prior to 18.2R3-S8; 18.3 versions prior to 18.3R3-S5; 18.4 versions prior to 18.4R3-S8; 19.1 versions prior to 19.1R3-S5; 19.2 versions prior to 19.2R1-S7, 19.2R3-S3; 19.3 versions prior to 19.3R2-S6, 19.3R3-S3; 19.4 versions prior to 19.4R1-S4, 19.4R2-S4, 19.4R3-S3; 20.1 versions prior to 20.1R2-S2, 20.1R3; 20.2 versions prior to 20.2R3-S1; 20.3 versions prior to 20.3R2-S1, 20.3R3. | |||||
| CVE-2021-24420 | 1 Emarketdesign | 1 Request A Quote | 2021-10-27 | 3.5 LOW | 5.4 MEDIUM |
| The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the 'All Quotes" table. | |||||
| CVE-2019-9508 | 1 Vertiv | 2 Avocent Umg-4000, Avocent Umg-4000 Firmware | 2021-10-26 | 3.5 LOW | 3.5 LOW |
| The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to stored XSS. A remote attacker authenticated with an administrator account could store a maliciously named file within the web application that would execute each time a user browsed to the page. | |||||
| CVE-2019-9541 | 1 Telos | 1 Automated Message Handling System | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| : Information Exposure vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5. | |||||
| CVE-2021-24444 | 1 Taxopress | 1 Taxopress | 2021-10-26 | 3.5 LOW | 4.8 MEDIUM |
| The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.7.0.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue. | |||||
| CVE-2021-24679 | 1 Coinmarketstats | 1 Bitcoin \/ Altcoin Payment Gateway For Woocommerce | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue | |||||
| CVE-2021-27746 | 1 Hcltechsw | 1 Connections | 2021-10-26 | 3.5 LOW | 5.4 MEDIUM |
| "HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability" | |||||
| CVE-2021-35228 | 1 Solarwinds | 1 Database Performance Analyzer | 2021-10-26 | 2.6 LOW | 4.7 MEDIUM |
| This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim. | |||||
| CVE-2015-9507 | 2 Easydigitaldownloads, Sandhillsdev | 2 Attach Accounts To Orders, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Attach Accounts to Orders extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9536 | 2 Easydigitaldownloads, Sandhillsdev | 2 Twenty-twelve, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Twenty-Twelve theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9535 | 2 Easydigitaldownloads, Sandhillsdev | 2 Shoppette, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Shoppette theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9533 | 2 Easydigitaldownloads, Sandhillsdev | 2 Lattice, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Lattice theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9532 | 2 Easydigitaldownloads, Sandhillsdev | 2 Digital Store, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Digital Store theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9530 | 2 Easydigitaldownloads, Sandhillsdev | 2 Upload File, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Upload File extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9528 | 2 Easydigitaldownloads, Sandhillsdev | 2 Software Licensing, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Software Licensing extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9526 | 2 Easydigitaldownloads, Sandhillsdev | 2 Reviews, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Reviews extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9525 | 2 Easydigitaldownloads, Sandhillsdev | 2 Recurring Payments, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Recurring Payments extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9506 | 2 Easydigitaldownloads, Sandhillsdev | 2 Amazon S3, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Amazon S3 extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9508 | 2 Easydigitaldownloads, Sandhillsdev | 2 Commissions, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Commissions extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9513 | 2 Easydigitaldownloads, Sandhillsdev | 2 Favorites, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Favorites extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9514 | 2 Easydigitaldownloads, Sandhillsdev | 2 Free Downloads, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Free Downloads extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9515 | 2 Easydigitaldownloads, Sandhillsdev | 2 Htaccess Editor, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) htaccess Editor extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9517 | 2 Easydigitaldownloads, Sandhillsdev | 2 Manual Purchases, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Manual Purchases extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9519 | 2 Easydigitaldownloads, Sandhillsdev | 2 Pdf Stamper, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) PDF Stamper extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9521 | 2 Easydigitaldownloads, Sandhillsdev | 2 Pushover Notifications, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Pushover Notifications extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9522 | 2 Easydigitaldownloads, Sandhillsdev | 2 Qr Code, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) QR Code extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9524 | 2 Easydigitaldownloads, Sandhillsdev | 2 Recount Earnings, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Recount Earnings extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9511 | 2 Easydigitaldownloads, Sandhillsdev | 2 Conditional Success Redirects, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Conditional Success Redirects extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9509 | 2 Easydigitaldownloads, Sandhillsdev | 2 Content Restriction, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Content Restriction extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9510 | 2 Easydigitaldownloads, Sandhillsdev | 2 Cross-sell And Upsell, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Cross-sell Upsell extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9512 | 2 Easydigitaldownloads, Sandhillsdev | 2 Csv Manager, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) CSV Manager extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9505 | 1 Sandhillsdev | 1 Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) core component 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 for WordPress has XSS because add_query_arg is misused. | |||||
| CVE-2015-9534 | 2 Easydigitaldownloads, Sandhillsdev | 2 Quota, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Quota theme for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9531 | 2 Easydigitaldownloads, Sandhillsdev | 2 Wish Lists, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Wish Lists extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9529 | 2 Easydigitaldownloads, Sandhillsdev | 2 Stripe, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Stripe extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9516 | 2 Easydigitaldownloads, Sandhillsdev | 2 Invoices, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9520 | 2 Easydigitaldownloads, Sandhillsdev | 2 Per Product Emails, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Per Product Emails extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9523 | 2 Easydigitaldownloads, Sandhillsdev | 2 Recommended Products, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Recommended Products extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9518 | 2 Easydigitaldownloads, Sandhillsdev | 2 Pdf Invoices, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) PDF Invoices extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2015-9527 | 2 Easydigitaldownloads, Sandhillsdev | 2 Simple Shipping, Easy Digital Downloads | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Digital Downloads (EDD) Simple Shipping extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |||||
| CVE-2020-36486 | 4 Apple, Blackberry, Google and 1 more | 4 Iphone Os, Blackberry Os, Android and 1 more | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| Swift File Transfer Mobile v1.1.2 and below was discovered to contain a cross-site scripting (XSS) vulnerability via the 'path' parameter of the 'list' and 'download' exception-handling. | |||||
| CVE-2020-36494 | 1 Dedecms | 1 Dedecms | 2021-10-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component mychannel_edit.php via the `filename`, `mid`, `userid`, and `templet' parameters. | |||||
| CVE-2020-36493 | 1 Dedecms | 1 Dedecms | 2021-10-26 | 3.5 LOW | 5.4 MEDIUM |
| DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component media_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters. | |||||
| CVE-2020-36501 | 1 Sugarcrm | 1 Sugarcrm | 2021-10-26 | 3.5 LOW | 5.4 MEDIUM |
| Multiple cross-site scripting (XSS) vulnerabilities in the Support module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the primary address state or alternate address state input fields. | |||||
| CVE-2020-36492 | 1 Dedecms | 1 Dedecms | 2021-10-26 | 3.5 LOW | 5.4 MEDIUM |
| DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component select_media.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters. | |||||
