Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-10102 2 Debian, Wordpress 2 Debian Linux, Wordpress 2018-05-18 4.3 MEDIUM 6.1 MEDIUM
Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.
CVE-2013-2137 1 Apache 1 Ofbiz 2018-05-18 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the "View Log" screen in the Webtools application in Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-0177 1 Apache 1 Ofbiz 2018-05-18 3.5 LOW N/A
Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x allow remote authenticated users to inject arbitrary web script or HTML via the (1) Screenlet.title or (2) Image.alt Widget attribute, as demonstrated by the parentPortalPageId parameter to exampleext/control/ManagePortalPages.
CVE-2012-1621 1 Apache 1 Ofbiz 2018-05-18 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.02 allow remote attackers to inject arbitrary web script or HTML via (1) a parameter array in freemarker templates, the (2) contentId or (3) mapKey parameter in a cms event request, which are not properly handled in an error message, or unspecified input in (4) an ajax request to the getServerError function in checkoutProcess.js or (5) a Webslinger component request. NOTE: some of these details are obtained from third party information.
CVE-2017-7298 1 Moodle 1 Moodle 2018-05-17 3.5 LOW 5.4 MEDIUM
In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.
CVE-2018-10135 1 Iscripts 1 Eswap 2018-05-17 4.3 MEDIUM 6.1 MEDIUM
iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel.
CVE-2018-0549 1 Cybozu 1 Garoon 2018-05-17 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.0 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-0551 1 Cybozu 1 Garoon 2018-05-17 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.1 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-0532 1 Cybozu 1 Garoon 2018-05-17 4.0 MEDIUM 2.7 LOW
Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of the Standard database via unspecified vectors.
CVE-2018-9999 1 Zulip 1 Zulip Server 2018-05-17 3.5 LOW 5.4 MEDIUM
In Zulip Server versions before 1.7.2, there was an XSS issue with user uploads and the (default) LOCAL_UPLOADS_DIR storage backend.
CVE-2018-9986 1 Zulip 1 Zulip Server 2018-05-17 4.3 MEDIUM 6.1 MEDIUM
In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor.
CVE-2018-8772 1 Coship 2 Rt3052, Rt3052 Firmware 2018-05-16 4.3 MEDIUM 6.1 MEDIUM
Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen.
CVE-2018-10318 1 Frogcms Project 1 Frogcms 2018-05-16 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has XSS via the admin/?/page/edit page[keywords] parameter, aka Edit Page Metadata.
CVE-2018-10321 1 Frogcms Project 1 Frogcms 2018-05-16 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.
CVE-2018-10320 1 Frogcms Project 1 Frogcms 2018-05-16 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has XSS via the admin/?/layout/edit layout[name] parameter, aka Edit Layout.
CVE-2018-10319 1 Frogcms Project 1 Frogcms 2018-05-16 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit snippet[name] parameter, aka Edit Snippet.
CVE-2017-1790 1 Ibm 2 Rational Doors Next Generation, Rational Requirements Composer 2018-05-16 3.5 LOW 5.4 MEDIUM
IBM DOORS Next Generation (DNG/RRC) 5.0, 5.0.1, 5.0.2, and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137035.
CVE-2018-7660 1 Opentext 1 Documentum D2 2018-05-16 3.5 LOW 5.4 MEDIUM
In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Reflected Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via the servlet/Download _docbase or _username parameter.
CVE-2018-7659 1 Opentext 1 Documentum D2 2018-05-16 3.5 LOW 5.4 MEDIUM
In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Stored Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via a filename of an uploaded image file.
CVE-2018-6935 1 Student Profile Management System Script Project 1 Student Profile Management System Script 2018-05-16 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall Student Profile Management System Script v2.0.6 has XSS via the Name field to list_student.php.