Vulnerabilities (CVE)

Filtered by CWE-79
Total 34649 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-1000856 1 Domainmod 1 Domainmod 2019-01-07 3.5 LOW 4.8 MEDIUM
DomainMOD version 4.09.03 and above. Also verified in the latest version 4.11.01 contains a Cross Site Scripting (XSS) vulnerability in Segment Name field in the segments page that can result in Arbitrary script can be executed on all users browsers who visit the affected page. This attack appear to be exploitable via Victim must visit the vulnerable page. This vulnerability appears to have been fixed in No fix yet.
CVE-2018-19933 1 Bolt 1 Bolt Cms 2019-01-07 4.3 MEDIUM 6.1 MEDIUM
Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry.
CVE-2017-18352 1 Google 1 Rendertron 2019-01-07 4.3 MEDIUM 6.1 MEDIUM
Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.
CVE-2018-20327 1 Chamilo 1 Chamilo Lms 2019-01-07 3.5 LOW 5.4 MEDIUM
Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.
CVE-2018-20328 1 Chamilo 1 Chamilo Lms 2019-01-07 3.5 LOW 5.4 MEDIUM
Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.
CVE-2018-1000813 1 Backdropcms 1 Backdrop Cms 2019-01-06 3.5 LOW 4.8 MEDIUM
Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom class names used on blocks and layouts. that can result in Execution of JavaScript from an unexpected source.. This attack appear to be exploitable via A user must be directed to an affected page while logged in.. This vulnerability appears to have been fixed in 1.11.1 and later.
CVE-2018-19828 1 Artica 1 Integria Ims 2019-01-04 4.3 MEDIUM 6.1 MEDIUM
Artica Integria IMS 5.0.83 has XSS via the search_string parameter.
CVE-2018-20564 1 Douco 1 Douphp 2019-01-04 3.5 LOW 4.8 MEDIUM
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product_category.php?rec=update has XSS via the cat_name parameter.
CVE-2018-20565 1 Douco 1 Douphp 2019-01-04 3.5 LOW 4.8 MEDIUM
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/nav.php?rec=update has XSS via the nav_name parameter.
CVE-2018-20557 1 Douco 1 Douphp 2019-01-04 3.5 LOW 4.8 MEDIUM
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/page.php?rec=edit has XSS via the page_name parameter.
CVE-2018-20558 1 Douco 1 Douphp 2019-01-04 3.5 LOW 4.8 MEDIUM
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/system.php?rec=update has XSS via the site_name parameter.
CVE-2018-20560 1 Douco 1 Douphp 2019-01-04 3.5 LOW 4.8 MEDIUM
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/show.php?rec=update has XSS via the show_name parameter.
CVE-2018-20559 1 Douco 1 Douphp 2019-01-04 3.5 LOW 4.8 MEDIUM
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product.php?rec=update has XSS via the name parameter.
CVE-2018-20561 1 Douco 1 Douphp 2019-01-04 3.5 LOW 4.8 MEDIUM
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/article.php?rec=update has XSS via the title parameter.
CVE-2018-20562 1 Douco 1 Douphp 2019-01-04 3.5 LOW 4.8 MEDIUM
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/article_category.php?rec=update has XSS via the cat_name parameter.
CVE-2018-20563 1 Douco 1 Douphp 2019-01-04 3.5 LOW 4.8 MEDIUM
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/mobile.php?rec=system&act=update has XSS via the mobile_name parameter.
CVE-2018-20597 1 Ucms Project 1 Ucms 2019-01-04 3.5 LOW 4.8 MEDIUM
UCMS 1.4.7 has XSS via the dir parameter in an index.php sadmin_fileedit action.
CVE-2018-20600 1 Ucms Project 1 Ucms 2019-01-04 4.3 MEDIUM 6.1 MEDIUM
sadmin\cedit.php in UCMS 1.4.7 has XSS via an index.php sadmin_cedit action.
CVE-2018-20601 1 Ucms Project 1 Ucms 2019-01-04 3.5 LOW 4.8 MEDIUM
UCMS 1.4.7 has XSS via the description parameter in an index.php list_editpost action.
CVE-2018-20530 1 Website Seller Script Project 1 Website Seller Script 2019-01-03 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a Profile field such as Company Address, a related issue to CVE-2018-15896.