Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-21001 1 Bologer 1 Anycomment 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
The anycomment plugin before 0.0.33 for WordPress has XSS.
CVE-2019-15479 1 Status Board Project 1 Status Board 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
Status Board 1.1.81 has reflected XSS via dashboard.ts.
CVE-2019-15227 1 Getflightpath 1 Flightpath 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead to cookie stealing and other malicious actions.
CVE-2019-15643 1 Etoilewebdesign 1 Ultimate Faq 2019-08-28 4.3 MEDIUM 6.1 MEDIUM
The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.
CVE-2018-6943 1 Ultimatemember 1 Ultimatemember 2019-08-27 4.3 MEDIUM 6.1 MEDIUM
core/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
CVE-2018-6944 1 Ultimatemember 1 Ultimate Member 2019-08-27 4.3 MEDIUM 6.1 MEDIUM
core/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it fails to properly sanitize user input passed to the $temp variable.
CVE-2018-19386 1 Solarwinds 1 Database Performance Analyzer 2019-08-27 4.3 MEDIUM 6.1 MEDIUM
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.
CVE-2016-6858 1 Sap 1 Hybris 2019-08-27 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the Create Employee feature in Hybris Management Console (HMC) in SAP Hybris before 5.0.4.11, 5.1.0.x before 5.1.0.11, 5.1.1.x before 5.1.1.12, 5.2.0.x and 5.3.0.x before 5.3.0.10, 5.4.x before 5.4.0.9, 5.5.0.x before 5.5.0.9, 5.5.1.x before 5.5.1.10, 5.6.x before 5.6.0.8, and 5.7.x before 5.7.0.9 allows remote authenticated users to inject arbitrary web script or HTML via the Name field.
CVE-2019-14221 1 1crm 1 1crm On-premise 2019-08-27 3.5 LOW 5.4 MEDIUM
1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation.
CVE-2018-20986 1 Advancedcustomfields 1 Advanced Custom Fields 2019-08-27 3.5 LOW 5.4 MEDIUM
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by authors.
CVE-2019-15488 1 Igniterealtime 1 Openfire 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
CVE-2019-15476 1 Former Project 1 Former 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
Former before 4.2.1 has XSS via a checkbox value.
CVE-2019-15482 1 Selectize-plugin-a11y Project 1 Selectize-plugin-a11y 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
selectize-plugin-a11y before 1.1.0 has XSS via the msg field.
CVE-2019-3966 1 Open-emr 1 Openemr 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the foreign_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
CVE-2019-11584 1 Atlassian 1 Jira 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the priority icon url of an issue priority.
CVE-2018-12101 1 Clippercms 1 Clippercms 2019-08-26 3.5 LOW 5.4 MEDIUM
CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields.
CVE-2019-14427 1 Webstudio 1 Ultimate Loan Manager 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
XSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes parameter with crafted JavaScript code.
CVE-2019-15487 1 Schoolexperience 1 Department For Education School Experience 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
DfE School Experience before v16333-GA has XSS via a teacher training URL.
CVE-2019-15492 1 It-novum 1 Openitcockpit 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.
CVE-2019-15489 1 Laracom 1 Laracom 2019-08-26 4.3 MEDIUM 6.1 MEDIUM
laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS.