Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-7936 1 Magento 1 Magento 2019-08-06 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to modify content block titles to inject malicious javascript.
CVE-2019-7937 1 Magento 1 Magento 2019-08-06 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to store product attributes to inject malicious javascript.
CVE-2019-7927 1 Magento 1 Magento 2019-08-06 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by an authenticated user with privileges to edit product content pages to inject malicious javascript.
CVE-2019-7939 1 Magento 1 Magento 2019-08-06 4.3 MEDIUM 6.1 MEDIUM
A reflected cross-site scripting vulnerability exists on the customer cart checkout page of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited by sending a victim a crafted URL that results in malicious javascript execution in the victim's browser.
CVE-2019-7869 1 Magento 1 Magento 2019-08-06 3.5 LOW 4.8 MEDIUM
A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with permissions to manage customer groups.
CVE-2013-7474 1 Windu 1 Windu Cms 2019-08-06 4.3 MEDIUM 6.1 MEDIUM
Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to admin/users.
CVE-2016-10851 1 Cpanel 1 Cpanel 2019-08-05 3.5 LOW 5.4 MEDIUM
cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).
CVE-2016-10854 1 Cpanel 1 Cpanel 2019-08-05 3.5 LOW 5.4 MEDIUM
cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).
CVE-2018-20900 1 Cpanel 1 Cpanel 2019-08-05 4.3 MEDIUM 6.1 MEDIUM
cPanel before 71.9980.37 allows stored XSS in the YUM autorepair functionality (SEC-399).
CVE-2019-14653 1 Ipandao 1 Editor.md 2019-08-05 4.3 MEDIUM 6.1 MEDIUM
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
CVE-2019-14517 1 Editor.md Project 1 Editor.md 2019-08-05 4.3 MEDIUM 6.1 MEDIUM
pandao Editor.md 1.5.0 allows XSS via the Javascript: string.
CVE-2019-12475 1 Microstrategy 1 Microstrategy Web 2019-08-05 4.3 MEDIUM 6.1 MEDIUM
In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation.
CVE-2019-14472 1 Zurmo 1 Zurmo 2019-08-05 4.3 MEDIUM 6.1 MEDIUM
Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO.
CVE-2019-11199 1 Dolibarr 1 Dolibarr Erp\/crm 2019-08-05 3.5 LOW 5.4 MEDIUM
Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link hosted on the same domain. The vulnerabilities could be exploited by low privileged users to target administrators. The viewimage.php page did not perform any contextual output encoding and would display the content within the uploaded file with a user-requested MIME type.
CVE-2017-18417 1 Cpanel 1 Cpanel 2019-08-05 3.5 LOW 5.4 MEDIUM
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).
CVE-2017-18418 1 Cpanel 1 Cpanel 2019-08-05 3.5 LOW 5.4 MEDIUM
cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).
CVE-2017-18419 1 Cpanel 1 Cpanel 2019-08-05 3.5 LOW 5.4 MEDIUM
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).
CVE-2017-18420 1 Cpanel 1 Cpanel 2019-08-05 3.5 LOW 5.4 MEDIUM
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).
CVE-2018-18570 1 Planonsoftware 1 Planon 2019-08-05 4.3 MEDIUM 6.1 MEDIUM
Planon before Live Build 41 has XSS.
CVE-2019-1010147 2 Bmc, Yellowfinbi 2 Remedy Smart Reporting, Yellowfin Bi 2019-08-05 3.5 LOW 5.4 MEDIUM
Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked and access admin functionality through their browser and control browser. The component is: MIAdminStyles.i4. The attack vector is: Victims are typically lured to a web site under the attacker's control; the XSS vulnerability on the target domain is silently exploited without the victim's knowledge. The fixed version is: 7.4 and later.