Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-10102 | 2 Debian, Wordpress | 2 Debian Linux, Wordpress | 2018-05-18 | 4.3 MEDIUM | 6.1 MEDIUM |
Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag. | |||||
CVE-2013-2137 | 1 Apache | 1 Ofbiz | 2018-05-18 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2013-0177 | 1 Apache | 1 Ofbiz | 2018-05-18 | 3.5 LOW | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x allow remote authenticated users to inject arbitrary web script or HTML via the (1) Screenlet.title or (2) Image.alt Widget attribute, as demonstrated by the parentPortalPageId parameter to exampleext/control/ManagePortalPages. | |||||
CVE-2012-1621 | 1 Apache | 1 Ofbiz | 2018-05-18 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.02 allow remote attackers to inject arbitrary web script or HTML via (1) a parameter array in freemarker templates, the (2) contentId or (3) mapKey parameter in a cms event request, which are not properly handled in an error message, or unspecified input in (4) an ajax request to the getServerError function in checkoutProcess.js or (5) a Webslinger component request. NOTE: some of these details are obtained from third party information. | |||||
CVE-2017-7298 | 1 Moodle | 1 Moodle | 2018-05-17 | 3.5 LOW | 5.4 MEDIUM |
In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element. | |||||
CVE-2018-10135 | 1 Iscripts | 1 Eswap | 2018-05-17 | 4.3 MEDIUM | 6.1 MEDIUM |
iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel. | |||||
CVE-2018-0549 | 1 Cybozu | 1 Garoon | 2018-05-17 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.0 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-0551 | 1 Cybozu | 1 Garoon | 2018-05-17 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.1 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2018-0532 | 1 Cybozu | 1 Garoon | 2018-05-17 | 4.0 MEDIUM | 2.7 LOW |
Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of the Standard database via unspecified vectors. | |||||
CVE-2018-9999 | 1 Zulip | 1 Zulip Server | 2018-05-17 | 3.5 LOW | 5.4 MEDIUM |
In Zulip Server versions before 1.7.2, there was an XSS issue with user uploads and the (default) LOCAL_UPLOADS_DIR storage backend. | |||||
CVE-2018-9986 | 1 Zulip | 1 Zulip Server | 2018-05-17 | 4.3 MEDIUM | 6.1 MEDIUM |
In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor. | |||||
CVE-2018-8772 | 1 Coship | 2 Rt3052, Rt3052 Firmware | 2018-05-16 | 4.3 MEDIUM | 6.1 MEDIUM |
Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen. | |||||
CVE-2018-10318 | 1 Frogcms Project | 1 Frogcms | 2018-05-16 | 3.5 LOW | 4.8 MEDIUM |
Frog CMS 0.9.5 has XSS via the admin/?/page/edit page[keywords] parameter, aka Edit Page Metadata. | |||||
CVE-2018-10321 | 1 Frogcms Project | 1 Frogcms | 2018-05-16 | 3.5 LOW | 4.8 MEDIUM |
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings. | |||||
CVE-2018-10320 | 1 Frogcms Project | 1 Frogcms | 2018-05-16 | 3.5 LOW | 4.8 MEDIUM |
Frog CMS 0.9.5 has XSS via the admin/?/layout/edit layout[name] parameter, aka Edit Layout. | |||||
CVE-2018-10319 | 1 Frogcms Project | 1 Frogcms | 2018-05-16 | 3.5 LOW | 4.8 MEDIUM |
Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit snippet[name] parameter, aka Edit Snippet. | |||||
CVE-2017-1790 | 1 Ibm | 2 Rational Doors Next Generation, Rational Requirements Composer | 2018-05-16 | 3.5 LOW | 5.4 MEDIUM |
IBM DOORS Next Generation (DNG/RRC) 5.0, 5.0.1, 5.0.2, and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137035. | |||||
CVE-2018-7660 | 1 Opentext | 1 Documentum D2 | 2018-05-16 | 3.5 LOW | 5.4 MEDIUM |
In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Reflected Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via the servlet/Download _docbase or _username parameter. | |||||
CVE-2018-7659 | 1 Opentext | 1 Documentum D2 | 2018-05-16 | 3.5 LOW | 5.4 MEDIUM |
In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Stored Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via a filename of an uploaded image file. | |||||
CVE-2018-6935 | 1 Student Profile Management System Script Project | 1 Student Profile Management System Script | 2018-05-16 | 3.5 LOW | 5.4 MEDIUM |
PHP Scripts Mall Student Profile Management System Script v2.0.6 has XSS via the Name field to list_student.php. |