Vulnerabilities (CVE)

Filtered by CWE-79
Total 34649 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-12272 1 Ximdex 1 Ximdex 2018-08-02 4.3 MEDIUM 6.1 MEDIUM
xowl/request.php in Ximdex 4.0 has XSS via the content parameter.
CVE-2018-5521 1 F5 13 Big-ip Access Policy Manager, Big-ip Advanced Firewall Manager, Big-ip Analytics and 10 more 2018-08-01 4.3 MEDIUM 6.1 MEDIUM
On F5 BIG-IP 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1, carefully crafted URLs can be used to reflect arbitrary content into GeoIP lookup responses, potentially exposing clients to XSS.
CVE-2018-12094 1 Dimofinf 1 Dimofinf Cms 2018-08-01 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-2018-12095 1 Oecms Project 1 Oecms 2018-08-01 3.5 LOW 5.4 MEDIUM
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php.
CVE-2016-9903 1 Mozilla 1 Firefox 2018-08-01 4.3 MEDIUM 6.1 MEDIUM
Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resource to be loaded as a document it could allow injecting content and script into an add-on's context. This vulnerability affects Firefox < 50.1.
CVE-2018-12030 1 Chevereto 1 Chevereto 2018-08-01 3.5 LOW 5.4 MEDIUM
Chevereto Free before 1.0.13 has XSS.
CVE-2018-11553 1 Sgin 1 Xiangyun Platform 2018-07-31 4.3 MEDIUM 6.1 MEDIUM
SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php.
CVE-2017-18286 1 Nzedb 1 Nzedb 2018-07-31 3.5 LOW 5.4 MEDIUM
nZEDb v0.7.3.3 has XSS in the 404 error page.
CVE-2018-9182 1 Lynxtechnology 1 Twonky Server 2018-07-31 4.3 MEDIUM 6.1 MEDIUM
Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.
CVE-2018-12111 1 Canon 1 Efi Printme 2018-07-30 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /wt3/mydocs.php URI.
CVE-2010-0432 1 Apache 1 Ofbiz 2018-07-30 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the productStoreId parameter to control/exportProductListing, (2) the partyId parameter to partymgr/control/viewprofile (aka partymgr/control/login), (3) the start parameter to myportal/control/showPortalPage, (4) an invalid URI beginning with /facility/control/ReceiveReturn (aka /crmsfa/control/ReceiveReturn or /cms/control/ReceiveReturn), (5) the contentId parameter (aka the entityName variable) to ecommerce/control/ViewBlogArticle, (6) the entityName parameter to webtools/control/FindGeneric, or the (7) subject or (8) content parameter to an unspecified component under ecommerce/control/contactus.
CVE-2018-12266 1 Hongcms Project 1 Hongcms 2018-07-26 4.3 MEDIUM 6.1 MEDIUM
system\errors\404.php in HongCMS 3.0.0 has XSS via crafted input that triggers a 404 HTTP status code.
CVE-2018-12353 1 Knowage-suite 1 Knowage 2018-07-24 4.3 MEDIUM 6.1 MEDIUM
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name field to the "Business Model's Catalogue" catalogue.
CVE-2018-11735 1 Ximdex 1 Ximdex 2018-07-23 4.3 MEDIUM 6.1 MEDIUM
index.php?action=createaccount in Ximdex 4.0 has XSS via the sname or fname parameter.
CVE-2018-11715 1 Recent Threads Project 1 Recent Threads 2018-07-18 3.5 LOW 5.4 MEDIUM
The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.
CVE-2018-1000202 1 Jenkins 1 Groovy Postbuild 2018-07-18 3.5 LOW 5.4 MEDIUM
A persisted cross-site scripting vulnerability exists in Jenkins Groovy Postbuild Plugin 2.3.1 and older in various Jelly files that allows attackers able to control build badge content to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.
CVE-2018-7747 1 Calderalabs 1 Caldera Forms 2018-07-17 3.5 LOW 4.8 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a greeting message, (2) the email transaction log, or (3) an imported form.
CVE-2018-11709 1 Gvectors 1 Wpforo Forum 2018-07-16 4.3 MEDIUM 6.1 MEDIUM
wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.
CVE-2012-6662 2 Jqueryui, Redhat 5 Jquery Ui, Enterprise Linux Desktop, Enterprise Linux Hpc Node and 2 more 2018-07-14 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.
CVE-2018-11568 1 Cactusthemes 1 Gameplan-event And Gym Fitness 2018-07-13 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS is possible in the GamePlan theme through 1.5.13.2 for WordPress because of insufficient input sanitization, as demonstrated by the s parameter. In some (but not all) cases, the '<' and '>' characters have &lt; and &gt; representations.