Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-20010 | 1 Domainmod | 1 Domainmod | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field. | |||||
CVE-2019-6263 | 1 Joomla | 1 Joomla\! | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allowed stored XSS. | |||||
CVE-2019-6261 | 1 Joomla | 1 Joomla\! | 2019-02-26 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in com_contact leads to a stored XSS vulnerability. | |||||
CVE-2019-6262 | 1 Joomla | 1 Joomla\! | 2019-02-26 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration helpurl settings allowed stored XSS. | |||||
CVE-2018-20240 | 1 Atlassian | 2 Crucible, Fisheye | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter. | |||||
CVE-2018-20241 | 1 Atlassian | 2 Crucible, Fisheye | 2019-02-26 | 3.5 LOW | 5.4 MEDIUM |
The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the wbuser parameter. | |||||
CVE-2019-6264 | 1 Joomla | 1 Joomla\! | 2019-02-26 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in mod_banners leads to a stored XSS vulnerability. | |||||
CVE-2019-9168 | 1 Woocommerce | 1 Woocommerce | 2019-02-26 | 4.3 MEDIUM | 6.1 MEDIUM |
WooCommerce before 3.5.5 allows XSS via a Photoswipe caption. | |||||
CVE-2018-19914 | 1 Domainmod | 1 Domainmod | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field. | |||||
CVE-2018-20011 | 1 Domainmod | 1 Domainmod | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field. | |||||
CVE-2018-16638 | 1 Modx | 1 Evolution Cms | 2019-02-26 | 3.5 LOW | 5.4 MEDIUM |
Evolution CMS 1.4.x allows XSS via the manager/ search parameter. | |||||
CVE-2018-20009 | 1 Domainmod | 1 Domainmod | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field. | |||||
CVE-2018-16637 | 1 Modx | 1 Evolution Cms | 2019-02-26 | 3.5 LOW | 5.4 MEDIUM |
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI. | |||||
CVE-2018-16632 | 1 Jupo | 1 Mezzanine | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
Mezzanine CMS v4.3.1 allows XSS via the /admin/blog/blogcategory/add/?_to_field=id&_popup=1 title parameter at admin/blog/blogpost/add/. | |||||
CVE-2018-19598 | 1 Statamic | 1 Statamic | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
Statamic 2.10.3 allows XSS via First Name or Last Name to the /users URI in an 'Add new user' request. | |||||
CVE-2018-19915 | 1 Domainmod | 1 Domainmod | 2019-02-26 | 3.5 LOW | 4.8 MEDIUM |
DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field. | |||||
CVE-2018-16635 | 1 Blackcat-cms | 1 Blackcat Cms | 2019-02-26 | 3.5 LOW | 5.4 MEDIUM |
Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php. | |||||
CVE-2019-9145 | 1 Hsycms | 1 Hsycms | 2019-02-26 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Hsycms V1.1. There is an XSS vulnerability via the name field to the /book page. | |||||
CVE-2018-16633 | 1 Pluck-cms | 1 Pluck | 2019-02-26 | 3.5 LOW | 5.4 MEDIUM |
Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title. | |||||
CVE-2018-16631 | 1 Intelliants | 1 Subrion Cms | 2019-02-26 | 3.5 LOW | 5.4 MEDIUM |
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter. |