Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-11549 1 Wuzhicms 1 Wuzhi Cms 2018-06-29 3.5 LOW 5.4 MEDIUM
An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq_10]= substring.
CVE-2018-11562 1 Misp 1 Misp 2018-06-29 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious link for an event view and then clicks on the deleted attributes quick filter.
CVE-2018-11583 1 Seacms 1 Seacms 2018-06-29 4.3 MEDIUM 6.1 MEDIUM
SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter.
CVE-2018-10379 1 Gitlab 1 Gitlab 2018-06-29 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability.
CVE-2018-11512 1 Creatiwity 1 Witycms 2018-06-29 3.5 LOW 4.8 MEDIUM
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to admin/settings/general.
CVE-2018-11532 1 Changuondyu Advanced Statistics Project 1 Changuondyu Advanced Statistics 2018-06-29 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field.
CVE-2018-11133 1 Quest 1 Kace System Management Appliance 2018-06-28 4.3 MEDIUM 6.1 MEDIUM
The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable to cross-site scripting.
CVE-2018-11430 1 Moderator Log Notes Project 1 Moderator Log Notes 2018-06-28 3.5 LOW 5.4 MEDIUM
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea.
CVE-2018-11557 1 Yiban 1 Easy Class Education Platform 2018-06-28 4.3 MEDIUM 6.1 MEDIUM
YIBAN Easy class education platform 2.0 has XSS via the articlelist.php k parameter.
CVE-2018-11487 1 Phpmywind 1 Phpmywind 2018-06-27 4.3 MEDIUM 6.1 MEDIUM
PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.
CVE-2018-11572 1 Clippercms 1 Clippercms 2018-06-27 3.5 LOW 5.4 MEDIUM
ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.
CVE-2018-11651 1 Graylog 1 Graylog 2018-06-27 4.3 MEDIUM 6.1 MEDIUM
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
CVE-2018-10382 1 Modx 1 Modx Revolution 2018-06-27 3.5 LOW 5.4 MEDIUM
MODX Revolution 2.6.3 has XSS.
CVE-2018-11649 1 Gethue 1 Hue 2018-06-27 4.3 MEDIUM 6.1 MEDIUM
Hue 3.12 has XSS via the /pig/save/ name and script parameters.
CVE-2018-11650 1 Graylog 1 Graylog 2018-06-27 4.3 MEDIUM 6.1 MEDIUM
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
CVE-2012-4484 2 Drupal, Trexart 2 Drupal, Campaignmonitor 2018-06-26 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the Campaign Monitor software itself (described on the campaignmonitor.com web site).
CVE-2018-11472 1 Monstra 1 Monstra 2018-06-26 4.3 MEDIUM 6.1 MEDIUM
Monstra CMS 3.0.4 has Reflected XSS during Login (i.e., the login parameter to admin/index.php).
CVE-2018-11339 1 Frappe 1 Erpnext 2018-06-26 4.3 MEDIUM 6.1 MEDIUM
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
CVE-2018-11473 1 Monstra 1 Monstra 2018-06-26 4.3 MEDIUM 6.1 MEDIUM
Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).
CVE-2018-11415 1 Sap 1 Internet Transaction Server 2018-06-26 4.3 MEDIUM 6.1 MEDIUM
SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product.