Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-13864 | 1 Elementor | 1 Elementor Page Builder | 2020-06-09 | 3.5 LOW | 5.4 MEDIUM |
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom links. | |||||
CVE-2020-13869 | 1 Verbb | 1 Comments | 2020-06-09 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name. | |||||
CVE-2020-13870 | 1 Verbb | 1 Comments | 2020-06-09 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name. | |||||
CVE-2020-13897 | 1 Hesk | 1 Hesk | 2020-06-09 | 4.3 MEDIUM | 6.1 MEDIUM |
HESK before 3.1.10 allows reflected XSS. | |||||
CVE-2020-3233 | 1 Cisco | 1 Iox | 2020-06-08 | 3.5 LOW | 5.4 MEDIUM |
A vulnerability in the web-based Local Manager interface of the Cisco IOx Application Framework could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based Local Manager interface of an affected device. The attacker must have valid Local Manager credentials. The vulnerability is due to insufficient validation of user-supplied input by the web-based Local Manager interface of the affected software. An attacker could exploit this vulnerability by injecting malicious code into a system settings tab. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected web interface or allow the attacker to access sensitive browser-based information. | |||||
CVE-2018-18625 | 1 Grafana | 1 Grafana | 2020-06-08 | 4.3 MEDIUM | 6.1 MEDIUM |
Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099. | |||||
CVE-2018-18624 | 1 Grafana | 1 Grafana | 2020-06-08 | 4.3 MEDIUM | 6.1 MEDIUM |
Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099. | |||||
CVE-2020-6640 | 1 Fortinet | 1 Fortianalyzer | 2020-06-07 | 3.5 LOW | 5.4 MEDIUM |
An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Description Area. | |||||
CVE-2020-4183 | 2 Ibm, Linux | 2 Security Guardium, Linux Kernel | 2020-06-05 | 4.3 MEDIUM | 6.1 MEDIUM |
IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 174739. | |||||
CVE-2020-7011 | 1 Elastic | 1 Elastic App Search | 2020-06-05 | 4.3 MEDIUM | 6.1 MEDIUM |
Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Reference UI injects a URL into a result, that URL will be rendered by the web browser. If an attacker is able to control the contents of such a field, they could execute arbitrary JavaScript in the victim�s web browser. | |||||
CVE-2018-12355 | 1 Eng | 1 Knowage | 2020-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue. | |||||
CVE-2018-10821 | 1 Blackcat-cms | 1 Blackcat Cms | 2020-06-04 | 3.5 LOW | 4.8 MEDIUM |
Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin role to inject arbitrary web script or HTML via the search panel. | |||||
CVE-2020-13796 | 1 Naviwebs | 1 Navigate Cms | 2020-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/structure/structure.class.php. | |||||
CVE-2020-13797 | 1 Naviwebs | 1 Navigate Cms | 2020-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/websites/website.class.php. | |||||
CVE-2020-13798 | 1 Naviwebs | 1 Navigate Cms | 2020-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/feeds/feed.class.php. | |||||
CVE-2014-9685 | 1 Vanillaforums | 2 Vanilla, Vanilla Forums | 2020-06-04 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2011-0526 | 1 Vanillaforums | 1 Vanilla | 2020-06-04 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in Vanilla Forums before 2.0.17 allows remote attackers to inject arbitrary web script or HTML via the Target parameter in a /entry/signin action. | |||||
CVE-2011-0909 | 1 Vanillaforums | 1 Vanilla | 2020-06-04 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526. | |||||
CVE-2011-1009 | 1 Vanillaforums | 1 Vanilla | 2020-06-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter. | |||||
CVE-2012-6556 | 1 Jspautsch | 1 Firstlastnames | 2020-06-04 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in the FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrary web script or HTML via the (1) User/FirstName or (2) User/LastName parameter to the edit user page. NOTE: some of these details are obtained from third party information. |