Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-10073 | 1 Joyplus-cms Project | 1 Joyplus-cms | 2018-05-14 | 3.5 LOW | 4.8 MEDIUM |
joyplus-cms 1.6.0 has XSS in manager/admin_vod.php via the keyword parameter. | |||||
CVE-2018-10128 | 1 Xyhcms Project | 1 Xyhcms | 2018-05-11 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in XYHCMS 3.5. It has XSS via the test parameter to index.php. | |||||
CVE-2018-9844 | 1 Iptanus | 1 Wordpress File Upload | 2018-05-11 | 4.3 MEDIUM | 6.1 MEDIUM |
The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS. | |||||
CVE-2018-10096 | 1 Joyplus-cms Project | 1 Joyplus-cms | 2018-05-11 | 3.5 LOW | 4.8 MEDIUM |
joyplus-cms 1.6.0 has XSS via the device_name parameter in a manager/admin_ajax.php?action=save flag=add request. | |||||
CVE-2014-6169 | 1 Ibm | 1 Forms Experience Builder | 2018-05-11 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.0 and 8.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 97777. | |||||
CVE-2018-6870 | 1 Website Seller Script Project | 1 Website Seller Script | 2018-05-11 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS exists in PHP Scripts Mall Website Seller Script 2.0.3 via the Listings Search feature. | |||||
CVE-2018-6902 | 1 Image Sharing Script Project | 1 Image Sharing Script | 2018-05-11 | 3.5 LOW | 5.4 MEDIUM |
PHP Scripts Mall Image Sharing Script 1.3.3 has XSS via the Full Name field in an Edit Profile action. | |||||
CVE-2018-6900 | 1 Website Broker Script Project | 1 Website Broker Script | 2018-05-11 | 3.5 LOW | 5.4 MEDIUM |
PHP Scripts Mall Website Broker Script 3.0.6 has XSS via the Last Name field on the My Profile page. | |||||
CVE-2018-9992 | 1 Frog Cms Project | 1 Frog Cms | 2018-05-11 | 3.5 LOW | 4.8 MEDIUM |
Frog CMS 0.9.5 has XSS via the name field of a new "File" or "Directory" on the admin/?/plugin/file_manager/browse/ screen. | |||||
CVE-2018-9991 | 1 Frog Cms Project | 1 Frog Cms | 2018-05-11 | 3.5 LOW | 4.8 MEDIUM |
Frog CMS 0.9.5 has XSS via the /admin/?/user/add Name or Username parameter. | |||||
CVE-2018-9928 | 1 Metinfo | 1 Metinfo | 2018-05-11 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in save.php in MetInfo 6.0 allows remote attackers to inject arbitrary web script or HTML via the webname or weburl parameter. | |||||
CVE-2018-1000154 | 1 Zammad | 1 Zammad | 2018-05-10 | 4.3 MEDIUM | 6.1 MEDIUM |
Zammad GmbH Zammad version 2.3.0 and earlier contains a Improper Neutralization of Script-Related HTML Tags in a Web Page (CWE-80) vulnerability in the subject of emails which are not html quoted in certain cases. This can result in the embedding and execution of java script code on users browser. This attack appear to be exploitable via the victim openning a ticket. This vulnerability appears to have been fixed in 2.3.1, 2.2.2 and 2.1.3. | |||||
CVE-2018-9172 | 1 Iptanus | 1 Wordpress File Upload | 2018-05-10 | 3.5 LOW | 5.4 MEDIUM |
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes. | |||||
CVE-2018-10052 | 1 Iscripts | 1 Supportdesk | 2018-05-09 | 3.5 LOW | 4.8 MEDIUM |
iScripts SupportDesk v4.3 has XSS via the admin/inteligentsearchresult.php txtinteligentsearch parameter. | |||||
CVE-2018-10051 | 1 Iscripts | 1 Supportdesk | 2018-05-09 | 3.5 LOW | 5.4 MEDIUM |
iScripts SupportDesk v4.3 has XSS via the staff/inteligentsearchresult.php txtinteligentsearch parameter. | |||||
CVE-2018-10049 | 1 Iscripts | 1 Eswap | 2018-05-09 | 3.5 LOW | 4.8 MEDIUM |
iScripts eSwap v2.4 has XSS via the "registration_settings.php" txtDate parameter in the Admin Panel. | |||||
CVE-2018-9857 | 1 Match Clone Script Project | 1 Match Clone Script | 2018-05-09 | 4.3 MEDIUM | 6.1 MEDIUM |
PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" screen). | |||||
CVE-2018-9328 | 1 Redbus Clone Script Project | 1 Redbus Clone Script | 2018-05-09 | 4.3 MEDIUM | 6.1 MEDIUM |
PHP Scripts Mall Redbus Clone Script 3.0.6 has XSS via the ter_from or tag parameter to results.php. | |||||
CVE-2018-7035 | 1 Gleezcms | 1 Gleez Cms | 2018-05-09 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in Gleez CMS 1.2.0 and 2.0 might allow remote attackers (users) to inject JavaScript via HTML content in an editor, which will result in Stored XSS when an Administrator tries to edit the same content, as demonstrated by use of the source editor for HTML mode in an Add Blog action. | |||||
CVE-2017-18098 | 1 Atlassian | 1 Jira | 2018-05-09 | 4.3 MEDIUM | 6.1 MEDIUM |
The searchrequest-xml resource in Atlassian Jira before version 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through various fields. |