Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-18491 1 Bestwebsoft 1 Contact Form 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The contact-form-plugin plugin before 4.0.6 for WordPress has multiple XSS issues.
CVE-2019-14987 1 Schben 1 Framework 2019-08-15 3.5 LOW 4.8 MEDIUM
Adive Framework through 2.0.7 is affected by XSS in the Create New Table and Create New Navigation Link functions.
CVE-2018-20962 1 Backpackforlaravel 1 Backpack\\crud 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type.
CVE-2018-20966 1 Booster 1 Booster For Woocommerce 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.
CVE-2018-14954 1 Squirrelmail 1 Squirrelmail 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute.
CVE-2018-14950 1 Squirrelmail 1 Squirrelmail 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack.
CVE-2018-14953 1 Squirrelmail 1 Squirrelmail 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.
CVE-2018-14952 1 Squirrelmail 1 Squirrelmail 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack.
CVE-2018-14951 1 Squirrelmail 1 Squirrelmail 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack.
CVE-2018-14955 1 Squirrelmail 1 Squirrelmail 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute).
CVE-2019-14976 1 Icmsdev 1 Icms 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter.
CVE-2015-9305 1 Flippercode 1 Google Map 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.
CVE-2019-14950 1 Wp-livechat 1 Wp Live Chat Support 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
CVE-2016-10879 1 Wp-livechat 1 Wp Live Chat Support 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.
CVE-2016-10877 1 Wp Editor Project 1 Wp Editor 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues.
CVE-2019-14967 1 Frappe 1 Frappe 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.
CVE-2017-18495 1 Mediaburst 1 Gravity Forms 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS.
CVE-2017-18497 1 W3eden 1 Live Forms 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The liveforms plugin before 3.4.0 for WordPress has XSS.
CVE-2017-18496 1 Bestwebsoft 1 Htaccess 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The htaccess plugin before 1.7.6 for WordPress has multiple XSS issues.
CVE-2017-18494 1 Bestwebsoft 1 Custom Search 2019-08-15 4.3 MEDIUM 6.1 MEDIUM
The custom-search-plugin plugin before 1.36 for WordPress has multiple XSS issues.