Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-15679 1 Btiteam 1 Xbtit 2018-11-05 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in BTITeam XBTIT 2.5.4. The "keywords" parameter in the search function available at /index.php?page=forums&action=search is vulnerable to reflected cross-site scripting.
CVE-2018-15678 1 Btiteam 1 Xbtit 2018-11-05 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in BTITeam XBTIT 2.5.4. The "act" parameter in the sign-up page available at /index.php?page=signup is vulnerable to reflected cross-site scripting.
CVE-2018-6643 1 Infoblox 1 Netmri 2018-11-05 4.3 MEDIUM 6.1 MEDIUM
Infoblox NetMRI 7.1.1 has Reflected Cross-Site Scripting via the /api/docs/index.php query parameter.
CVE-2018-15562 1 Isweb 1 Isweb 2018-11-05 4.3 MEDIUM 6.1 MEDIUM
CMS ISWEB 3.5.3 has XSS via the ordineRis, sezioneRicerca, or oggettiRicerca parameter to index.php.
CVE-2018-16298 1 1234n 1 Minicms 2018-11-02 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in MiniCMS 1.10. There is an mc-admin/post.php?tag= XSS vulnerability for a state=delete, state=draft, or state=publish request.
CVE-2018-16313 1 Bludit 1 Bludit 2018-11-02 4.3 MEDIUM 6.1 MEDIUM
Bludit 2.3.4 allows XSS via a user name.
CVE-2018-16325 1 Get-simple 1 Getsimple Cms 2018-11-02 4.3 MEDIUM 6.1 MEDIUM
There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.
CVE-2018-16622 1 Html-js 1 Doracms 2018-11-02 3.5 LOW 5.4 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) discription or (2) comments field, related to users/userAddContent.
CVE-2018-16285 1 Userproplugin 1 Userpro 2018-11-02 4.3 MEDIUM 6.1 MEDIUM
The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php.
CVE-2018-16654 1 Zurmo 1 Zurmo Crm 2018-11-02 4.3 MEDIUM 6.1 MEDIUM
Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1.
CVE-2018-16728 1 Feindura 1 Feindura 2018-11-02 3.5 LOW 5.4 MEDIUM
feindura 2.0.7 allows XSS via the tags field of a new page created at index.php?category=0&page=new.
CVE-2018-16980 1 Dotcms 1 Dotcms 2018-11-02 4.3 MEDIUM 6.1 MEDIUM
dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters.
CVE-2017-15427 3 Debian, Google, Redhat 5 Debian Linux, Chrome, Enterprise Linux Desktop and 2 more 2018-11-02 4.3 MEDIUM 6.1 MEDIUM
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.
CVE-2018-0715 1 Qnap 1 Photo Station 2018-11-02 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.
CVE-2018-15546 1 Accusoft 1 Prizmdoc 2018-11-02 4.3 MEDIUM 6.1 MEDIUM
Accusoft PrizmDoc version 13.3 and earlier contains a Stored Cross-Site Scripting issue through a crafted PDF file.
CVE-2018-15880 1 Joomla 1 Joomla\! 2018-11-02 3.5 LOW 5.4 MEDIUM
An issue was discovered in Joomla! before 3.8.12. Inadequate output filtering on the user profile page could lead to a stored XSS attack.
CVE-2018-8426 1 Microsoft 3 Sharepoint Enterprise Server 2013, Sharepoint Enterprise Server 2016, Sharepoint Server 2010 2018-11-02 3.5 LOW 5.4 MEDIUM
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.
CVE-2018-17046 1 Translate Man Project 1 Translate Man 2018-11-02 4.3 MEDIUM 6.1 MEDIUM
translate man before 2018-08-21 has XSS via containers/outputBox/outputBox.vue and store/index.js.
CVE-2018-16727 1 Razorcms 1 Razorcms 2018-11-02 3.5 LOW 5.4 MEDIUM
razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component.
CVE-2018-16726 1 Razorcms 1 Razorcms 2018-11-02 3.5 LOW 5.4 MEDIUM
razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component.