Vulnerabilities (CVE)

Filtered by CWE-79
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-5004 1 Ibm 9 Engineering Lifecycle Optimization - Engineering Insights, Engineering Requirements Quality Assistant On-premises, Engineering Test Management and 6 more 2021-08-04 3.5 LOW 5.4 MEDIUM
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192957.
CVE-2020-20699 1 S-cms 1 S-cms 2021-08-03 3.5 LOW 4.8 MEDIUM
A cross site scripting (XSS) vulnerability in S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Copyright text box under Basic Settings.
CVE-2020-18158 1 Hucart 1 Hucart 2021-08-03 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in HuCart 5.7.4 via nickname in index.php.
CVE-2020-21854 1 Tidesec 1 Wdscanner 2021-08-03 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting vulnerabiity exists in WDScanner 1.1 in the system management page.
CVE-2020-15948 1 Egain 1 Chat 2021-08-03 4.3 MEDIUM 6.1 MEDIUM
eGain Chat 15.5.5 allows XSS via the Name (aka full_name) field.
CVE-2020-20700 1 S-cms 1 S-cms 2021-08-03 3.5 LOW 4.8 MEDIUM
A stored cross site scripting (XSS) vulnerability in /app/form_add/of S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Title Entry text box.
CVE-2020-19118 1 Yzmcms 1 Yzmcms 2021-08-03 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerabiity in YzmCMS 5.2 via the site_code parameter in admin/index/init.html.
CVE-2020-20701 1 S-cms 1 S-cms 2021-08-03 3.5 LOW 4.8 MEDIUM
A stored cross site scripting (XSS) vulnerability in /app/config/of S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2021-37534 1 Misp 1 Misp 2021-08-03 3.5 LOW 5.4 MEDIUM
app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.
CVE-2020-22765 1 Nukeviet 1 Nukeviet 2021-08-03 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.
CVE-2021-25791 1 Online Doctor Appointment System Php Full Source Code Project 1 Online Doctor Appointment System Php Full Source Code 2021-08-03 3.5 LOW 5.4 MEDIUM
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.
CVE-2021-1599 1 Cisco 1 Unified Customer Voice Portal 2021-08-03 3.5 LOW 5.4 MEDIUM
A vulnerability in the web-based management interface of Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack against a user. This vulnerability is due to insufficient input validation of a parameter that is used by the web-based management interface. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute arbitrary code in the context of the interface, access sensitive, browser-based information, or cause an affected device to reboot under certain conditions.
CVE-2021-20111 1 Tecnick 1 Tcexam 2021-08-02 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_filemanager.php could upload a malicious javascript payload which would be triggered when another user views the file.
CVE-2021-20112 1 Tecnick 1 Tcexam 2021-08-02 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_select_mediafile.php could upload a malicious javascript payload which would be triggered when another user views the file.
CVE-2020-26563 1 Objectplanet 1 Opinio 2021-08-02 4.3 MEDIUM 6.1 MEDIUM
ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if input to survey/admin/*.do is accepted from untrusted users.)
CVE-2021-37742 1 Misp 1 Misp 2021-08-02 3.5 LOW 5.4 MEDIUM
app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.
CVE-2021-36605 1 Engineercms Project 1 Engineercms 2021-08-02 3.5 LOW 5.4 MEDIUM
engineercms 1.03 is vulnerable to Cross Site Scripting (XSS). There is no escaping in the nickname field on the user list page. When viewing this page, the JavaScript code will be executed in the user's browser.
CVE-2021-37743 1 Misp 1 Misp 2021-08-02 3.5 LOW 5.4 MEDIUM
app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.
CVE-2021-35208 1 Zimbra 1 Collaboration 2021-08-02 3.5 LOW 5.4 MEDIUM
An issue was discovered in ZmMailMsgView.js in the Calendar Invite component in Zimbra Collaboration Suite 8.8.x before 8.8.15 Patch 23. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.
CVE-2021-3159 1 Landray 1 Landray Ekp 2021-08-02 3.5 LOW 5.4 MEDIUM
A stored cross site scripting (XSS) vulnerability in the /sys/attachment/uploaderServlet component of Landray EKP V12.0.9.R.20160325 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG, SHTML, or MHT file.
CVE-2021-3619 1 Rapid7 1 Velociraptor 2021-08-02 3.5 LOW 4.8 MEDIUM
Rapid7 Velociraptor 0.5.9 and prior is vulnerable to a post-authentication persistent cross-site scripting (XSS) issue, where an authenticated user could abuse MIME filetype sniffing to embed executable code on a malicious upload. This issue was fixed in version 0.6.0. Note that login rights to Velociraptor is nearly always reserved for trusted and verified users with IT security backgrounds.
CVE-2020-7390 1 Sage 2 Syracuse, X3 2021-08-02 3.5 LOW 5.4 MEDIUM
Sage X3 Stored XSS Vulnerability on ‘Edit’ Page of User Profile. An authenticated user can pass XSS strings the "First Name," "Last Name," and "Email Address" fields of this web application component. Updates are available for on-premises versions of Version 12 (components shipped with Syracuse 12.10.0 and later) of Sage X3. Other on-premises versions of Sage X3 are unaffected or unsupported by the vendor.
CVE-2021-22522 1 Microfocus 1 Verastream Host Integrator 2021-08-02 6.8 MEDIUM 7.1 HIGH
Reflected Cross-Site Scripting vulnerability in Micro Focus Verastream Host Integrator, affecting version version 7.8 Update 1 and earlier versions. The vulnerability could allow disclosure of confidential data.
CVE-2021-37464 1 Nchsoftware 1 Quorum 2021-07-30 3.5 LOW 5.4 MEDIUM
In NCH Quorum v2.03 and earlier, XSS exists via Conference Description (stored).
CVE-2021-37463 1 Nchsoftware 1 Quorum 2021-07-30 3.5 LOW 5.4 MEDIUM
In NCH Quorum v2.03 and earlier, XSS exists via User Display Name (stored).
CVE-2021-26224 1 Fantastic Blog Project 1 Fantastic Blog 2021-07-30 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in SourceCodester Fantastic-Blog-CMS V 1.0 allows remote attackers to inject arbitrary web script or HTML via the search field to search.php.
CVE-2021-37465 1 Nchsoftware 1 Quorum 2021-07-30 3.5 LOW 5.4 MEDIUM
In NCH Quorum v2.03 and earlier, XSS exists via /uploaddoc?id= (reflected).
CVE-2021-37466 1 Nchsoftware 1 Quorum 2021-07-30 3.5 LOW 5.4 MEDIUM
In NCH Quorum v2.03 and earlier, XSS exists via /conference?id= (reflected).
CVE-2021-25197 1 Content Management System Project 1 Content Management System 2021-07-30 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in SourceCodester Content Management System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter to content_management_system\admin\new_content.php
CVE-2021-27332 1 Casap Automated Enrollment System Project 1 Casap Automated Enrollment System 2021-07-30 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the class_name parameter to update_class.php.
CVE-2021-37467 1 Nchsoftware 1 Quorum 2021-07-30 3.5 LOW 5.4 MEDIUM
In NCH Quorum v2.03 and earlier, XSS exists via /conferencebrowseuploadfile?confid= (reflected).
CVE-2021-37470 1 Nchsoftware 1 Webdictate 2021-07-30 3.5 LOW 5.4 MEDIUM
In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user can add or modify the affected field to inject arbitrary JavaScript.
CVE-2021-30049 1 Sysaid 1 Sysaid 2021-07-30 4.3 MEDIUM 6.1 MEDIUM
SysAid 20.3.64 b14 is affected by Cross Site Scripting (XSS) via a /KeepAlive.jsp?stamp= URI.
CVE-2021-26230 1 Casap Automated Enrollment System Project 1 Casap Automated Enrollment System 2021-07-30 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the user information to save_user.php.
CVE-2021-26227 1 Casap Automated Enrollment System Project 1 Casap Automated Enrollment System 2021-07-30 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the student information parameters to edit_stud.php.
CVE-2014-6393 1 Openjsf 1 Express 2021-07-30 4.3 MEDIUM 6.1 MEDIUM
The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.
CVE-2020-23234 1 Lavalite 1 Lavalite 2021-07-30 3.5 LOW 4.8 MEDIUM
Cross Site Scripting (XSS) vulnerabiity exists in LavaLite CMS 5.8.0 via the Menu Blocks feature, which can be bypassed by using HTML event handlers, such as "ontoggle,".
CVE-2021-32745 1 Collabora 1 Online 2021-07-30 4.3 MEDIUM 6.1 MEDIUM
Collabora Online is a collaborative online office suite. A reflected XSS vulnerability was found in Collabora Online prior to version 6.4.9-5. An attacker could inject unescaped HTML into a variable as they created the Collabora Online iframe, and execute scripts inside the context of the Collabora Online iframe. This would give access to a small set of user settings stored in the browser, as well as the session's authentication token which was also passed in at iframe creation time. The issue is patched in Collabora Online 6.4.9-5. Collabora Online 4.2 is not affected.
CVE-2020-25205 1 Mimosa 6 B5, B5 Firmware, B5c and 3 more 2021-07-30 4.3 MEDIUM 6.1 MEDIUM
The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 is vulnerable to stored XSS in the set_banner() function of /var/www/core/controller/index.php. An unauthenticated attacker may set the contents of the /mnt/jffs2/banner.txt file, stored on the device's filesystem, to contain arbitrary JavaScript. The file contents are then used as part of a welcome/banner message presented to unauthenticated users who visit the login page for the web console. This vulnerability does not occur in the older 1.5.x firmware versions.
CVE-2020-23238 1 Evo 1 Evolution Cms 2021-07-30 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in Evolution CMS 2.0.2 via the Document Manager feature.
CVE-2020-23239 1 Textpattern 1 Textpattern 2021-07-30 3.5 LOW 4.8 MEDIUM
Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.
CVE-2020-23240 1 Cmsmadesimple 1 Cms Made Simple 2021-07-30 3.5 LOW 4.8 MEDIUM
Cross Site Scripting (XSS) vulnerablity in CMS Made Simple 2.2.14 via the Logic field in the Content Manager feature.
CVE-2020-23241 1 Cmsmadesimple 1 Cms Made Simple 2021-07-30 3.5 LOW 4.8 MEDIUM
Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.14 in "Extra" via 'News > Article" feature.
CVE-2020-23242 1 Naviwebs 1 Navigatecms 2021-07-30 3.5 LOW 4.8 MEDIUM
Cross Site Scripting (XSS) vulnerability in NavigateCMS 2.9 when performing a Create or Edit via the Tools feature.
CVE-2020-23243 1 Naviwebs 1 Navigatecms 2021-07-30 3.5 LOW 4.8 MEDIUM
Cross Site Scripting (XSS) vulnerability in NavigateCMS NavigateCMS 2.9 via the name="wrong_path_redirect" feature.
CVE-2019-9978 1 Warfareplugins 2 Social Warfare, Social Warfare Pro 2021-07-30 4.3 MEDIUM 6.1 MEDIUM
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.
CVE-2021-26799 1 Omeka 1 Omeka 2021-07-29 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in admin/files/edit in Omeka Classic <=2.7 allows remote attackers to inject arbitrary web script or HTML.
CVE-2021-33501 1 Overwolf 1 Overwolf 2021-07-29 9.3 HIGH 9.6 CRITICAL
Overwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL.
CVE-2021-32667 1 Typo3 1 Typo3 2021-07-29 3.5 LOW 5.4 MEDIUM
TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When _Page TSconfig_ settings are not properly encoded, corresponding page preview module (_Web>View_) is vulnerable to persistent cross-site scripting. A valid backend user account is needed to exploit this vulnerability. TYPO3 versions 9.5.29, 10.4.18, 11.3.1 contain a patch for this issue.
CVE-2021-32668 1 Typo3 1 Typo3 2021-07-29 3.5 LOW 4.8 MEDIUM
TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When error messages are not properly encoded, the components _QueryGenerator_ and _QueryView_ are vulnerable to both reflected and persistent cross-site scripting. A valid backend user account having administrator privileges is needed to exploit this vulnerability. TYPO3 versions 9.5.29, 10.4.18, 11.3.1 contain a patch for this issue.