Vulnerabilities (CVE)

Filtered by CWE-79
Total 34649 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-10135 1 Iscripts 1 Eswap 2018-05-17 4.3 MEDIUM 6.1 MEDIUM
iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel.
CVE-2018-0551 1 Cybozu 1 Garoon 2018-05-17 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.1 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-0549 1 Cybozu 1 Garoon 2018-05-17 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.0 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-0532 1 Cybozu 1 Garoon 2018-05-17 4.0 MEDIUM 2.7 LOW
Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of the Standard database via unspecified vectors.
CVE-2018-9999 1 Zulip 1 Zulip Server 2018-05-17 3.5 LOW 5.4 MEDIUM
In Zulip Server versions before 1.7.2, there was an XSS issue with user uploads and the (default) LOCAL_UPLOADS_DIR storage backend.
CVE-2018-9986 1 Zulip 1 Zulip Server 2018-05-17 4.3 MEDIUM 6.1 MEDIUM
In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor.
CVE-2018-8772 1 Coship 2 Rt3052, Rt3052 Firmware 2018-05-16 4.3 MEDIUM 6.1 MEDIUM
Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen.
CVE-2018-10318 1 Frogcms Project 1 Frogcms 2018-05-16 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has XSS via the admin/?/page/edit page[keywords] parameter, aka Edit Page Metadata.
CVE-2018-10321 1 Frogcms Project 1 Frogcms 2018-05-16 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.
CVE-2018-10320 1 Frogcms Project 1 Frogcms 2018-05-16 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has XSS via the admin/?/layout/edit layout[name] parameter, aka Edit Layout.
CVE-2018-10319 1 Frogcms Project 1 Frogcms 2018-05-16 3.5 LOW 4.8 MEDIUM
Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit snippet[name] parameter, aka Edit Snippet.
CVE-2017-1790 1 Ibm 2 Rational Doors Next Generation, Rational Requirements Composer 2018-05-16 3.5 LOW 5.4 MEDIUM
IBM DOORS Next Generation (DNG/RRC) 5.0, 5.0.1, 5.0.2, and 6.0 through 6.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137035.
CVE-2018-7660 1 Opentext 1 Documentum D2 2018-05-16 3.5 LOW 5.4 MEDIUM
In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Reflected Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via the servlet/Download _docbase or _username parameter.
CVE-2018-7659 1 Opentext 1 Documentum D2 2018-05-16 3.5 LOW 5.4 MEDIUM
In OpenText Documentum D2 Webtop v4.6.0030 build 059, a Stored Cross-Site Scripting Vulnerability could potentially be exploited by malicious users to compromise the affected system via a filename of an uploaded image file.
CVE-2018-6935 1 Student Profile Management System Script Project 1 Student Profile Management System Script 2018-05-16 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall Student Profile Management System Script v2.0.6 has XSS via the Name field to list_student.php.
CVE-2018-6904 1 Car Rental Script Project 1 Car Rental Script 2018-05-16 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the User Name field in an Edit Profile action.
CVE-2018-9330 1 Coremail 1 Coremail Xt 2018-05-16 3.5 LOW 5.4 MEDIUM
register.jsp in Coremail XT3.0 allows stored XSS, as demonstrated by the third form field to a URI under register/, a different vulnerability than CVE-2015-6942.
CVE-2018-10026 1 Yzmcms 1 Yzmcms 2018-05-16 3.5 LOW 4.8 MEDIUM
The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the valid function in application/wechat/controller/index.class.php.
CVE-2018-5227 1 Atlassian 1 Application Links 2018-05-16 3.5 LOW 4.8 MEDIUM
Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attackers with administration rights to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the display url of a configured application link.
CVE-2018-9155 1 Open-audit 1 Open-audit 2018-05-16 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the Admin->Logs section (with a logs?logs.type= URI) and the Manage->Attributes section (via the "Name (display)" field to the attributes/create URI).