Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-21001 | 1 Bologer | 1 Anycomment | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
The anycomment plugin before 0.0.33 for WordPress has XSS. | |||||
CVE-2019-15479 | 1 Status Board Project | 1 Status Board | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
Status Board 1.1.81 has reflected XSS via dashboard.ts. | |||||
CVE-2019-15227 | 1 Getflightpath | 1 Flightpath | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead to cookie stealing and other malicious actions. | |||||
CVE-2019-15643 | 1 Etoilewebdesign | 1 Ultimate Faq | 2019-08-28 | 4.3 MEDIUM | 6.1 MEDIUM |
The ultimate-faqs plugin before 1.8.22 for WordPress has XSS. | |||||
CVE-2018-6943 | 1 Ultimatemember | 1 Ultimatemember | 2019-08-27 | 4.3 MEDIUM | 6.1 MEDIUM |
core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable. | |||||
CVE-2018-6944 | 1 Ultimatemember | 1 Ultimate Member | 2019-08-27 | 4.3 MEDIUM | 6.1 MEDIUM |
core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable. | |||||
CVE-2018-19386 | 1 Solarwinds | 1 Database Performance Analyzer | 2019-08-27 | 4.3 MEDIUM | 6.1 MEDIUM |
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI. | |||||
CVE-2016-6858 | 1 Sap | 1 Hybris | 2019-08-27 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in the Create Employee feature in Hybris Management Console (HMC) in SAP Hybris before 5.0.4.11, 5.1.0.x before 5.1.0.11, 5.1.1.x before 5.1.1.12, 5.2.0.x and 5.3.0.x before 5.3.0.10, 5.4.x before 5.4.0.9, 5.5.0.x before 5.5.0.9, 5.5.1.x before 5.5.1.10, 5.6.x before 5.6.0.8, and 5.7.x before 5.7.0.9 allows remote authenticated users to inject arbitrary web script or HTML via the Name field. | |||||
CVE-2019-14221 | 1 1crm | 1 1crm On-premise | 2019-08-27 | 3.5 LOW | 5.4 MEDIUM |
1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation. | |||||
CVE-2018-20986 | 1 Advancedcustomfields | 1 Advanced Custom Fields | 2019-08-27 | 3.5 LOW | 5.4 MEDIUM |
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors. | |||||
CVE-2019-15488 | 1 Igniterealtime | 1 Openfire | 2019-08-26 | 4.3 MEDIUM | 6.1 MEDIUM |
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test. | |||||
CVE-2019-15476 | 1 Former Project | 1 Former | 2019-08-26 | 4.3 MEDIUM | 6.1 MEDIUM |
Former before 4.2.1 has XSS via a checkbox value. | |||||
CVE-2019-15482 | 1 Selectize-plugin-a11y Project | 1 Selectize-plugin-a11y | 2019-08-26 | 4.3 MEDIUM | 6.1 MEDIUM |
selectize-plugin-a11y before 1.1.0 has XSS via the msg field. | |||||
CVE-2019-3966 | 1 Open-emr | 1 Openemr | 2019-08-26 | 4.3 MEDIUM | 6.1 MEDIUM |
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the foreign_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session. | |||||
CVE-2019-11584 | 1 Atlassian | 1 Jira | 2019-08-26 | 4.3 MEDIUM | 6.1 MEDIUM |
The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the priority icon url of an issue priority. | |||||
CVE-2018-12101 | 1 Clippercms | 1 Clippercms | 2019-08-26 | 3.5 LOW | 5.4 MEDIUM |
CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields. | |||||
CVE-2019-14427 | 1 Webstudio | 1 Ultimate Loan Manager | 2019-08-26 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes parameter with crafted JavaScript code. | |||||
CVE-2019-15487 | 1 Schoolexperience | 1 Department For Education School Experience | 2019-08-26 | 4.3 MEDIUM | 6.1 MEDIUM |
DfE School Experience before v16333-GA has XSS via a teacher training URL. | |||||
CVE-2019-15492 | 1 It-novum | 1 Openitcockpit | 2019-08-26 | 4.3 MEDIUM | 6.1 MEDIUM |
openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21. | |||||
CVE-2019-15489 | 1 Laracom | 1 Laracom | 2019-08-26 | 4.3 MEDIUM | 6.1 MEDIUM |
laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS. |