Total
34649 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2018-11430 | 1 Moderator Log Notes Project | 1 Moderator Log Notes | 2018-06-28 | 3.5 LOW | 5.4 MEDIUM |
| An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea. | |||||
| CVE-2018-11557 | 1 Yiban | 1 Easy Class Education Platform | 2018-06-28 | 4.3 MEDIUM | 6.1 MEDIUM |
| YIBAN Easy class education platform 2.0 has XSS via the articlelist.php k parameter. | |||||
| CVE-2018-11487 | 1 Phpmywind | 1 Phpmywind | 2018-06-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php. | |||||
| CVE-2018-11572 | 1 Clippercms | 1 Clippercms | 2018-06-27 | 3.5 LOW | 5.4 MEDIUM |
| ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI. | |||||
| CVE-2018-10382 | 1 Modx | 1 Modx Revolution | 2018-06-27 | 3.5 LOW | 5.4 MEDIUM |
| MODX Revolution 2.6.3 has XSS. | |||||
| CVE-2018-11651 | 1 Graylog | 1 Graylog | 2018-06-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx. | |||||
| CVE-2018-11649 | 1 Gethue | 1 Hue | 2018-06-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| Hue 3.12 has XSS via the /pig/save/ name and script parameters. | |||||
| CVE-2018-11650 | 1 Graylog | 1 Graylog | 2018-06-27 | 4.3 MEDIUM | 6.1 MEDIUM |
| Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js. | |||||
| CVE-2012-4484 | 2 Drupal, Trexart | 2 Drupal, Campaignmonitor | 2018-06-27 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the Campaign Monitor software itself (described on the campaignmonitor.com web site). | |||||
| CVE-2018-11472 | 1 Monstra | 1 Monstra | 2018-06-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| Monstra CMS 3.0.4 has Reflected XSS during Login (i.e., the login parameter to admin/index.php). | |||||
| CVE-2018-11339 | 1 Frappe | 1 Erpnext | 2018-06-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment. | |||||
| CVE-2018-11473 | 1 Monstra | 1 Monstra | 2018-06-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration). | |||||
| CVE-2018-11415 | 1 Sap | 1 Internet Transaction Server | 2018-06-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product. | |||||
| CVE-2018-11366 | 1 Loginizer | 1 Loginizer | 2018-06-26 | 4.3 MEDIUM | 6.1 MEDIUM |
| init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandled. This is fixed in 1.4.0. | |||||
| CVE-2018-11443 | 1 Easyservice Billing Project | 1 Easyservice Billing | 2018-06-25 | 4.3 MEDIUM | 6.1 MEDIUM |
| The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0. | |||||
| CVE-2017-7840 | 1 Mozilla | 1 Firefox | 2018-06-25 | 4.3 MEDIUM | 6.1 MEDIUM |
| JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved bookmarks. If the resulting exported HTML file is later opened in a browser this JavaScript will be executed. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks if users were convinced to add malicious tags to bookmarks, export them, and then open the resulting file. This vulnerability affects Firefox < 57. | |||||
| CVE-2017-7834 | 1 Mozilla | 1 Firefox | 2018-06-25 | 4.3 MEDIUM | 6.1 MEDIUM |
| A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for bypasses of the policy including the execution of JavaScript. In prior versions when "data:" documents also inherited the context of the original page this would allow for potential cross-site scripting (XSS) attacks. This vulnerability affects Firefox < 57. | |||||
| CVE-2017-7839 | 1 Mozilla | 1 Firefox | 2018-06-25 | 4.3 MEDIUM | 6.1 MEDIUM |
| Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScript to be executed instead of being blocked. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks where users are convinced to copy and paste text into the addressbar. This vulnerability affects Firefox < 57. | |||||
| CVE-2018-10649 | 1 Citrix | 1 Xenmobile Server | 2018-06-25 | 4.3 MEDIUM | 6.1 MEDIUM |
| There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3. | |||||
| CVE-2018-11332 | 1 Clippercms | 1 Clippercms | 2018-06-25 | 3.5 LOW | 4.8 MEDIUM |
| Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted site name to the manager/processors/save_settings.processor.php file. | |||||
