Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-23832 1 Car Rental Management System Project 1 Car Rental Management System 2020-10-13 4.3 MEDIUM 6.1 MEDIUM
A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System v1.0 allows unauthenticated remote attackers to harvest an admin login session cookie and steal an admin session upon an admin login.
CVE-2020-4741 1 Ibm 1 Infosphere Information Server 2020-10-13 3.5 LOW 5.4 MEDIUM
IBM InfoSphere Information Server 11.5 and 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188197.
CVE-2020-4680 1 Ibm 1 Security Guardium 2020-10-13 3.5 LOW 5.4 MEDIUM
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186426.
CVE-2020-4679 1 Ibm 1 Security Guardium 2020-10-13 3.5 LOW 4.8 MEDIUM
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186424.
CVE-2020-4681 1 Ibm 1 Security Guardium 2020-10-13 3.5 LOW 5.4 MEDIUM
IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 186427.
CVE-2020-25830 1 Mantisbt 1 Mantisbt 2020-10-13 3.5 LOW 4.8 MEDIUM
An issue was discovered in MantisBT before 2.24.3. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when attempting to update said custom field via bug_actiongroup_page.php.
CVE-2020-25288 1 Mantisbt 1 Mantisbt 2020-10-13 3.5 LOW 4.8 MEDIUM
An issue was discovered in MantisBT before 2.24.3. When editing an Issue in a Project where a Custom Field with a crafted Regular Expression property is used, improper escaping of the corresponding form input's pattern attribute allows HTML injection and, if CSP settings permit, execution of arbitrary JavaScript.
CVE-2020-5631 1 Cmonos 1 Cmonos 2020-10-13 4.3 MEDIUM 6.1 MEDIUM
Stored cross-site scripting vulnerability in CMONOS.JP ver2.0.20191009 and earlier allows remote attackers to inject arbitrary script via unspecified vectors.
CVE-2020-26166 1 Qdpm 1 Qdpm 2020-10-13 3.5 LOW 5.4 MEDIUM
The file upload functionality in qdPM 9.1 doesn't check the file description, which allows remote authenticated attackers to inject web script or HTML via the attachments info parameter, aka XSS. This can occur during creation of a ticket, project, or task.
CVE-2019-19393 1 Rittal 2 Cmc Pu Iii 7030.000, Cmc Pu Iii 7030.000 Firmware 2020-10-13 4.3 MEDIUM 6.1 MEDIUM
The Web application on Rittal CMC PU III 7030.000 V3.00 V3.11.00_2 to V3.15.70_4 devices fails to sanitize user input on the system configurations page. This allows an attacker to backdoor the device with HTML and browser-interpreted content (such as JavaScript or other client-side scripts) as the content is always displayed after and before login. Persistent XSS allows an attacker to modify displayed content or to change the victim's information. Successful exploitation requires access to the web management interface, either with valid credentials or a hijacked session.
CVE-2020-12245 1 Grafana 1 Grafana 2020-10-10 4.3 MEDIUM 6.1 MEDIUM
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
CVE-2020-2290 1 Jenkins 1 Active Choices 2020-10-09 3.5 LOW 5.4 MEDIUM
Jenkins Active Choices Plugin 2.4 and earlier does not escape some return values of sandboxed scripts for Reactive Reference Parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
CVE-2020-2289 1 Jenkins 1 Active Choices 2020-10-09 3.5 LOW 5.4 MEDIUM
Jenkins Active Choices Plugin 2.4 and earlier does not escape the name and description of build parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
CVE-2020-7676 1 Angularjs 1 Angular.js 2020-10-09 3.5 LOW 5.4 MEDIUM
angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes parsing behavior, leading to possibly unsanitizing code.
CVE-2019-4725 1 Ibm 1 Security Access Manager 2020-10-09 4.3 MEDIUM 6.1 MEDIUM
IBM Security Access Manager Appliance 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172131.
CVE-2020-14223 1 Hcltech 1 Digital Experience 2020-10-08 4.3 MEDIUM 6.1 MEDIUM
HCL Digital Experience 8.5, 9.0, 9.5 is susceptible to cross-site scripting (XSS). The vulnerability could be employed in a reflected or non-persistent XSS attack.
CVE-2020-13339 1 Gitlab 1 Gitlab 2020-10-08 6.0 MEDIUM 6.5 MEDIUM
An issue has been discovered in GitLab affecting all versions before 13.2.10, 13.3.7 and 13.4.2: XSS in SVG File Preview. Overall impact is limited due to the current user only being impacted.
CVE-2020-15231 1 Mapfish 1 Print 2020-10-08 4.3 MEDIUM 6.1 MEDIUM
In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting.
CVE-2020-26134 1 Livehelperchat 1 Live Helper Chat 2020-10-08 4.3 MEDIUM 6.1 MEDIUM
Live Helper Chat before 3.44v allows stored XSS in chat messages with an operator via BBCode.
CVE-2020-13337 1 Gitlab 1 Gitlab 2020-10-08 3.5 LOW 4.8 MEDIUM
An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload to be added as a group name.