Vulnerabilities (CVE)

Filtered by CWE-79
Total 34649 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-11430 1 Moderator Log Notes Project 1 Moderator Log Notes 2018-06-28 3.5 LOW 5.4 MEDIUM
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea.
CVE-2018-11557 1 Yiban 1 Easy Class Education Platform 2018-06-28 4.3 MEDIUM 6.1 MEDIUM
YIBAN Easy class education platform 2.0 has XSS via the articlelist.php k parameter.
CVE-2018-11487 1 Phpmywind 1 Phpmywind 2018-06-27 4.3 MEDIUM 6.1 MEDIUM
PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.
CVE-2018-11572 1 Clippercms 1 Clippercms 2018-06-27 3.5 LOW 5.4 MEDIUM
ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.
CVE-2018-10382 1 Modx 1 Modx Revolution 2018-06-27 3.5 LOW 5.4 MEDIUM
MODX Revolution 2.6.3 has XSS.
CVE-2018-11651 1 Graylog 1 Graylog 2018-06-27 4.3 MEDIUM 6.1 MEDIUM
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
CVE-2018-11649 1 Gethue 1 Hue 2018-06-27 4.3 MEDIUM 6.1 MEDIUM
Hue 3.12 has XSS via the /pig/save/ name and script parameters.
CVE-2018-11650 1 Graylog 1 Graylog 2018-06-27 4.3 MEDIUM 6.1 MEDIUM
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
CVE-2012-4484 2 Drupal, Trexart 2 Drupal, Campaignmonitor 2018-06-27 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the Campaign Monitor software itself (described on the campaignmonitor.com web site).
CVE-2018-11472 1 Monstra 1 Monstra 2018-06-26 4.3 MEDIUM 6.1 MEDIUM
Monstra CMS 3.0.4 has Reflected XSS during Login (i.e., the login parameter to admin/index.php).
CVE-2018-11339 1 Frappe 1 Erpnext 2018-06-26 4.3 MEDIUM 6.1 MEDIUM
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
CVE-2018-11473 1 Monstra 1 Monstra 2018-06-26 4.3 MEDIUM 6.1 MEDIUM
Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).
CVE-2018-11415 1 Sap 1 Internet Transaction Server 2018-06-26 4.3 MEDIUM 6.1 MEDIUM
SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product.
CVE-2018-11366 1 Loginizer 1 Loginizer 2018-06-26 4.3 MEDIUM 6.1 MEDIUM
init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandled. This is fixed in 1.4.0.
CVE-2018-11443 1 Easyservice Billing Project 1 Easyservice Billing 2018-06-25 4.3 MEDIUM 6.1 MEDIUM
The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
CVE-2017-7840 1 Mozilla 1 Firefox 2018-06-25 4.3 MEDIUM 6.1 MEDIUM
JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved bookmarks. If the resulting exported HTML file is later opened in a browser this JavaScript will be executed. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks if users were convinced to add malicious tags to bookmarks, export them, and then open the resulting file. This vulnerability affects Firefox < 57.
CVE-2017-7834 1 Mozilla 1 Firefox 2018-06-25 4.3 MEDIUM 6.1 MEDIUM
A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for bypasses of the policy including the execution of JavaScript. In prior versions when "data:" documents also inherited the context of the original page this would allow for potential cross-site scripting (XSS) attacks. This vulnerability affects Firefox < 57.
CVE-2017-7839 1 Mozilla 1 Firefox 2018-06-25 4.3 MEDIUM 6.1 MEDIUM
Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScript to be executed instead of being blocked. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks where users are convinced to copy and paste text into the addressbar. This vulnerability affects Firefox < 57.
CVE-2018-10649 1 Citrix 1 Xenmobile Server 2018-06-25 4.3 MEDIUM 6.1 MEDIUM
There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.
CVE-2018-11332 1 Clippercms 1 Clippercms 2018-06-25 3.5 LOW 4.8 MEDIUM
Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted site name to the manager/processors/save_settings.processor.php file.