Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-15679 | 1 Btiteam | 1 Xbtit | 2018-11-05 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in BTITeam XBTIT 2.5.4. The "keywords" parameter in the search function available at /index.php?page=forums&action=search is vulnerable to reflected cross-site scripting. | |||||
CVE-2018-15678 | 1 Btiteam | 1 Xbtit | 2018-11-05 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in BTITeam XBTIT 2.5.4. The "act" parameter in the sign-up page available at /index.php?page=signup is vulnerable to reflected cross-site scripting. | |||||
CVE-2018-6643 | 1 Infoblox | 1 Netmri | 2018-11-05 | 4.3 MEDIUM | 6.1 MEDIUM |
Infoblox NetMRI 7.1.1 has Reflected Cross-Site Scripting via the /api/docs/index.php query parameter. | |||||
CVE-2018-15562 | 1 Isweb | 1 Isweb | 2018-11-05 | 4.3 MEDIUM | 6.1 MEDIUM |
CMS ISWEB 3.5.3 has XSS via the ordineRis, sezioneRicerca, or oggettiRicerca parameter to index.php. | |||||
CVE-2018-16298 | 1 1234n | 1 Minicms | 2018-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in MiniCMS 1.10. There is an mc-admin/post.php?tag= XSS vulnerability for a state=delete, state=draft, or state=publish request. | |||||
CVE-2018-16313 | 1 Bludit | 1 Bludit | 2018-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
Bludit 2.3.4 allows XSS via a user name. | |||||
CVE-2018-16325 | 1 Get-simple | 1 Getsimple Cms | 2018-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field. | |||||
CVE-2018-16622 | 1 Html-js | 1 Doracms | 2018-11-02 | 3.5 LOW | 5.4 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) discription or (2) comments field, related to users/userAddContent. | |||||
CVE-2018-16285 | 1 Userproplugin | 1 Userpro | 2018-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php. | |||||
CVE-2018-16654 | 1 Zurmo | 1 Zurmo Crm | 2018-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1. | |||||
CVE-2018-16728 | 1 Feindura | 1 Feindura | 2018-11-02 | 3.5 LOW | 5.4 MEDIUM |
feindura 2.0.7 allows XSS via the tags field of a new page created at index.php?category=0&page=new. | |||||
CVE-2018-16980 | 1 Dotcms | 1 Dotcms | 2018-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters. | |||||
CVE-2017-15427 | 3 Debian, Google, Redhat | 5 Debian Linux, Chrome, Enterprise Linux Desktop and 2 more | 2018-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar. | |||||
CVE-2018-0715 | 1 Qnap | 1 Photo Station | 2018-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application. | |||||
CVE-2018-15546 | 1 Accusoft | 1 Prizmdoc | 2018-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
Accusoft PrizmDoc version 13.3 and earlier contains a Stored Cross-Site Scripting issue through a crafted PDF file. | |||||
CVE-2018-15880 | 1 Joomla | 1 Joomla\! | 2018-11-02 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a stored XSS attack. | |||||
CVE-2018-8426 | 1 Microsoft | 3 Sharepoint Enterprise Server 2013, Sharepoint Enterprise Server 2016, Sharepoint Server 2010 | 2018-11-02 | 3.5 LOW | 5.4 MEDIUM |
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. | |||||
CVE-2018-17046 | 1 Translate Man Project | 1 Translate Man | 2018-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
translate man before 2018-08-21 has XSS via containers/outputBox/outputBox.vue and store/index.js. | |||||
CVE-2018-16727 | 1 Razorcms | 1 Razorcms | 2018-11-02 | 3.5 LOW | 5.4 MEDIUM |
razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component. | |||||
CVE-2018-16726 | 1 Razorcms | 1 Razorcms | 2018-11-02 | 3.5 LOW | 5.4 MEDIUM |
razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component. |