Vulnerabilities (CVE)

Filtered by CWE-79
Total 34649 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-11403 1 Domainmod 1 Domainmod 2018-06-25 3.5 LOW 5.4 MEDIUM
DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.
CVE-2018-11471 1 Getcockpit 1 Cockpit 2018-06-25 3.5 LOW 5.4 MEDIUM
Cockpit 0.5.5 has XSS via a collection, form, or region.
CVE-2018-6378 1 Joomla 1 Joomla\! 2018-06-22 4.3 MEDIUM 6.1 MEDIUM
In Joomla! Core before 3.8.8, inadequate filtering of file and folder names leads to various XSS attack vectors in the media manager.
CVE-2018-4931 1 Adobe 1 Experience Manager 2018-06-22 4.3 MEDIUM 6.1 MEDIUM
Adobe Experience Manager versions 6.1 and earlier have an exploitable stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2018-4930 1 Adobe 1 Experience Manager 2018-06-22 4.3 MEDIUM 6.1 MEDIUM
Adobe Experience Manager versions 6.3 and earlier have an exploitable Cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2018-4929 1 Adobe 1 Experience Manager 2018-06-22 4.3 MEDIUM 6.1 MEDIUM
Adobe Experience Manager versions 6.2 and earlier have an exploitable stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2018-11328 1 Joomla 1 Joomla\! 2018-06-22 2.6 LOW 4.7 MEDIUM
An issue was discovered in Joomla! Core before 3.8.8. Under specific circumstances (a redirect issued with a URI containing a username and password when the Location: header cannot be used), a lack of escaping the user-info component of the URI could result in an XSS vulnerability.
CVE-2018-11326 1 Joomla 1 Joomla\! 2018-06-22 3.5 LOW 4.8 MEDIUM
An issue was discovered in Joomla! Core before 3.8.8. Inadequate input filtering leads to a multiple XSS vulnerabilities. Additionally, the default filtering settings could potentially allow users of the default Administrator user group to perform a XSS attack.
CVE-2018-11404 1 Domainmod 1 Domainmod 2018-06-22 4.3 MEDIUM 6.1 MEDIUM
DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.
CVE-2018-11330 1 Pluck-cms 1 Pluck 2018-06-22 3.5 LOW 4.8 MEDIUM
An issue was discovered in Pluck before 4.7.6. There is authenticated stored XSS because the character set for filenames is not properly restricted.
CVE-2018-11101 1 Signal 1 Signal-desktop 2018-06-19 4.3 MEDIUM 6.1 MEDIUM
Open Whisper Signal (aka Signal-Desktop) through 1.10.1 allows XSS via a resource location specified in an attribute of a SCRIPT, IFRAME, or IMG element, leading to JavaScript execution after a reply, a different vulnerability than CVE-2018-10994. The attacker needs to send HTML code directly as a message, and then reply to that message to trigger this vulnerability. The Signal-Desktop software fails to sanitize specific HTML elements that can be used to inject HTML code into remote chat windows when replying to an HTML message. Specifically the IMG and IFRAME elements can be used to include remote or local resources. For example, the use of an IFRAME element enables full code execution, allowing an attacker to download/upload files, information, etc. The SCRIPT element was also found to be injectable. On the Windows operating system, the CSP fails to prevent remote inclusion of resources via the SMB protocol. In this case, remote execution of JavaScript can be achieved by referencing the script on an SMB share within an IFRAME element, for example: <IFRAME src=\\DESKTOP-XXXXX\Temp\test.html> and then replying to it. The included JavaScript code is then executed automatically, without any interaction needed from the user. The vulnerability can be triggered in the Signal-Desktop client by sending a specially crafted message and then replying to it with any text or content in the reply (it doesn't matter).
CVE-2018-0579 1 Webdados 1 Open Graph For Facebook\, Google\+ And Twitter Card Tags 2018-06-19 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Open Graph for Facebook, Google+ and Twitter Card Tags plugin prior to version 2.2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-11245 1 Misp-project 1 Misp 2018-06-19 4.3 MEDIUM 6.1 MEDIUM
app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes.
CVE-2018-10326 1 Printeron 1 Printeron 2018-06-19 3.5 LOW 5.4 MEDIUM
PrinterOn Enterprise 4.1.3 suffers from multiple authenticated stored XSS vulnerabilities via the (1) department field in the printer configuration, (2) description field in the print server configuration, and (3) username field for authentication to print as guest.
CVE-2018-1147 1 Tenable 1 Nessus 2018-06-19 3.5 LOW 5.4 MEDIUM
In Nessus before 7.1.0, a XSS vulnerability exists due to improper input validation. A remote authenticated attacker could create and upload a .nessus file, which may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session. In other scenarios, XSS could also occur by altering variables from the Advanced Settings.
CVE-2017-16860 1 Atlassian 1 Application Links 2018-06-19 4.3 MEDIUM 6.1 MEDIUM
The invalidRedirectUrl template in Atlassian Application Links before version 5.2.7, from version 5.3.0 before version 5.3.4 and from version 5.4.0 before version 5.4.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the redirectUrl parameter link in the redirect warning message.
CVE-2018-10810 1 Livezilla 1 Livezilla 2018-06-19 4.3 MEDIUM 6.1 MEDIUM
chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HTTP header.
CVE-2018-10306 1 Ilias 1 Ilias 2018-06-19 4.3 MEDIUM 6.1 MEDIUM
Services/Form/classes/class.ilDateDurationInputGUI.php and Services/Form/classes/class.ilDateTimeInputGUI.php in ILIAS 5.1.x through 5.3.x before 5.3.4 allow XSS via an invalid date.
CVE-2017-7583 1 Ilias 1 Ilias 2018-06-19 4.3 MEDIUM 6.1 MEDIUM
ILIAS before 5.2.3 has XSS via SVG documents.
CVE-2017-15538 1 Ilias 1 Ilias 2018-06-19 3.5 LOW 5.4 MEDIUM
Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenticated user to inject JavaScript to gain administrator privileges, related to the setParameter function in Services/MediaObjects/classes/class.ilMediaItem.php.