Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-11549 | 1 Wuzhicms | 1 Wuzhi Cms | 2018-06-29 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq_10]= substring. | |||||
CVE-2018-11562 | 1 Misp | 1 Misp | 2018-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious link for an event view and then clicks on the deleted attributes quick filter. | |||||
CVE-2018-11583 | 1 Seacms | 1 Seacms | 2018-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter. | |||||
CVE-2018-10379 | 1 Gitlab | 1 Gitlab | 2018-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability. | |||||
CVE-2018-11512 | 1 Creatiwity | 1 Witycms | 2018-06-29 | 3.5 LOW | 4.8 MEDIUM |
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to admin/settings/general. | |||||
CVE-2018-11532 | 1 Changuondyu Advanced Statistics Project | 1 Changuondyu Advanced Statistics | 2018-06-29 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field. | |||||
CVE-2018-11133 | 1 Quest | 1 Kace System Management Appliance | 2018-06-28 | 4.3 MEDIUM | 6.1 MEDIUM |
The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable to cross-site scripting. | |||||
CVE-2018-11430 | 1 Moderator Log Notes Project | 1 Moderator Log Notes | 2018-06-28 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea. | |||||
CVE-2018-11557 | 1 Yiban | 1 Easy Class Education Platform | 2018-06-28 | 4.3 MEDIUM | 6.1 MEDIUM |
YIBAN Easy class education platform 2.0 has XSS via the articlelist.php k parameter. | |||||
CVE-2018-11487 | 1 Phpmywind | 1 Phpmywind | 2018-06-27 | 4.3 MEDIUM | 6.1 MEDIUM |
PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php. | |||||
CVE-2018-11572 | 1 Clippercms | 1 Clippercms | 2018-06-27 | 3.5 LOW | 5.4 MEDIUM |
ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI. | |||||
CVE-2018-11651 | 1 Graylog | 1 Graylog | 2018-06-27 | 4.3 MEDIUM | 6.1 MEDIUM |
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx. | |||||
CVE-2018-10382 | 1 Modx | 1 Modx Revolution | 2018-06-27 | 3.5 LOW | 5.4 MEDIUM |
MODX Revolution 2.6.3 has XSS. | |||||
CVE-2018-11649 | 1 Gethue | 1 Hue | 2018-06-27 | 4.3 MEDIUM | 6.1 MEDIUM |
Hue 3.12 has XSS via the /pig/save/ name and script parameters. | |||||
CVE-2018-11650 | 1 Graylog | 1 Graylog | 2018-06-27 | 4.3 MEDIUM | 6.1 MEDIUM |
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js. | |||||
CVE-2012-4484 | 2 Drupal, Trexart | 2 Drupal, Campaignmonitor | 2018-06-26 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the Campaign Monitor software itself (described on the campaignmonitor.com web site). | |||||
CVE-2018-11472 | 1 Monstra | 1 Monstra | 2018-06-26 | 4.3 MEDIUM | 6.1 MEDIUM |
Monstra CMS 3.0.4 has Reflected XSS during Login (i.e., the login parameter to admin/index.php). | |||||
CVE-2018-11339 | 1 Frappe | 1 Erpnext | 2018-06-26 | 4.3 MEDIUM | 6.1 MEDIUM |
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment. | |||||
CVE-2018-11473 | 1 Monstra | 1 Monstra | 2018-06-26 | 4.3 MEDIUM | 6.1 MEDIUM |
Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration). | |||||
CVE-2018-11415 | 1 Sap | 1 Internet Transaction Server | 2018-06-26 | 4.3 MEDIUM | 6.1 MEDIUM |
SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product. |