Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-10136 1 Iscripts 1 Uberforx 2018-05-21 4.3 MEDIUM 6.1 MEDIUM
iScripts UberforX 2.2 has Stored XSS in the "manage_settings" section of the Admin Panel via a value field to the /cms?section=manage_settings&action=edit URI.
CVE-2018-8071 1 Mautic 1 Mautic 2018-05-21 4.3 MEDIUM 6.1 MEDIUM
Mautic before v2.13.0 has stored XSS via a theme config file.
CVE-2018-9987 1 Zulip 1 Zulip Server 2018-05-21 4.3 MEDIUM 6.1 MEDIUM
In Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2, there was an XSS issue with muting notifications.
CVE-2018-9990 1 Zulip 1 Zulip Server 2018-05-21 4.3 MEDIUM 6.1 MEDIUM
In Zulip Server versions before 1.7.2, there was an XSS issue with stream names in topic typeahead.
CVE-2018-10250 1 Icmsdev 1 Icms 2018-05-21 3.5 LOW 5.4 MEDIUM
iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management keyword search.
CVE-2018-10183 1 Bigtreecms 1 Bigtree Cms 2018-05-21 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in BigTree 4.2.22. There is cross-site scripting (XSS) in /core/inc/lib/less.php/test/index.php because of a $_SERVER['REQUEST_URI'] echo, as demonstrated by the dir parameter in a file=charsets action.
CVE-2018-10138 1 Catalooksupport 1 .netstore 2018-05-21 4.3 MEDIUM 6.1 MEDIUM
The CATALooK.netStore module through 7.2.8 for DNN (formerly DotNetNuke) allows XSS via the /ViewEditGoogleMaps.aspx PortalID or CATSkin parameter, or the /ImageViewer.aspx link or desc parameter.
CVE-2018-10110 1 D-link 2 Dir-615 T1, Dir-615 T1 Firmware 2018-05-21 3.5 LOW 4.8 MEDIUM
D-Link DIR-615 T1 devices allow XSS via the Add User feature.
CVE-2018-1000163 1 Projectfloodlight 1 Floodlight 2018-05-21 4.3 MEDIUM 6.1 MEDIUM
Floodlight version 1.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in the web console that can result in javascript injections into the web page. This attack appears to be exploitable via the victim browsing the web console.
CVE-2018-1000162 1 Parsedown 1 Parsedown 2018-05-21 4.3 MEDIUM 6.1 MEDIUM
Parsedown version prior to 1.7.0 contains a Cross Site Scripting (XSS) vulnerability in `setMarkupEscaped` for escaping HTML that can result in JavaScript code execution. This attack appears to be exploitable via specially crafted markdown that allows it to side step HTML escaping by breaking AST boundaries. This vulnerability appears to have been fixed in 1.7.0 and later.
CVE-2018-1000160 1 Risingstack 1 Protect 2018-05-21 4.3 MEDIUM 6.1 MEDIUM
RisingStack protect version 1.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in isXss() function in lib/rules/xss.js that can result in dangerous XSS strings being validated as safe. This attack appears to be exploitable via A number of XSS strings(26) detailed in the GitHub issue #16.
CVE-2016-2279 1 Rockwellautomation 15 Compactlogix 1769-l16er-bb1b, Compactlogix 1769-l18er-bb1b, Compactlogix 1769-l18erm-bb1b and 12 more 2018-05-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-1486 1 Ibm 1 Cognos Business Intelligence 2018-05-18 4.3 MEDIUM 6.1 MEDIUM
IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128624.
CVE-2014-0883 1 Ibm 1 Power Hardware Management Console 2018-05-18 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM Power Hardware Management Console (HMC) 7R7.1.0, 7R7.2.0, 7R7.3.0 through 7R7.3.5, 7R7.7.0 through SP3, and 7R7.8.0 before SP1 allows remote attackers to inject arbitrary web script or HTML via the user name on the logon screen. IBM X-Force ID: 91163.
CVE-2018-9169 1 Zblogcn 1 Z-blogphp 2018-05-18 3.5 LOW 4.8 MEDIUM
Z-BlogPHP 1.5.1 has XSS via the zb_users/plugin/AppCentre/plugin_edit.php app_id parameter. The component must be accessed directly by an administrator, or through CSRF.
CVE-2018-10298 1 Discuz 1 Discuzx 2018-05-18 3.5 LOW 5.4 MEDIUM
Discuz! DiscuzX through X3.4 has reflected XSS via forum.php?mod=post&action=newthread because data/template/1_diy_portal_view.tpl.php does not restrict the content.
CVE-2018-10297 1 Discuz 1 Discuzx 2018-05-18 3.5 LOW 5.4 MEDIUM
Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IMG elements associated with remote images.
CVE-2018-10108 1 D-link 2 Dir-815, Dir-815 Firmware 2018-05-18 4.3 MEDIUM 6.1 MEDIUM
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the Treturn parameter to /htdocs/webinc/js/bsc_sms_inbox.php.
CVE-2018-10107 1 D-link 2 Dir-815, Dir-815 Firmware 2018-05-18 4.3 MEDIUM 6.1 MEDIUM
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the RESULT parameter to /htdocs/webinc/js/info.php.
CVE-2018-10097 1 Smartscriptsolutions 1 Domain Trader 2018-05-18 4.3 MEDIUM 6.1 MEDIUM
XSS exists in Domain Trader 2.5.3 via the recoverlogin.php email_address parameter.