Vulnerabilities (CVE)

Filtered by CWE-79
Total 36939 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-5293 1 Gd Rating System Project 1 Gd Rating System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.
CVE-2018-5292 1 Gd Rating System Project 1 Gd Rating System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
CVE-2018-5288 1 Gd Rating System Project 1 Gd Rating System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
CVE-2018-5286 1 Gd Rating System Project 1 Gd Rating System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-about page.
CVE-2018-5284 1 Wpscoop 1 Imageinject 2024-11-21 3.5 LOW 4.8 MEDIUM
The ImageInject plugin 1.15 for WordPress has XSS via the flickr_appid parameter to wp-admin/options-general.php.
CVE-2018-5281 1 Sonicwall 8 Nsa 250m, Nsa 2600, Nsa 2650 and 5 more 2024-11-21 3.5 LOW 5.4 MEDIUM
SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens.
CVE-2018-5280 1 Sonicwall 8 Nsa 250m, Nsa 2600, Nsa 2650 and 5 more 2024-11-21 3.5 LOW 5.4 MEDIUM
SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.
CVE-2018-5263 1 Stackideas 1 Easydiscuss 2024-11-21 3.5 LOW 5.4 MEDIUM
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.
CVE-2018-5249 1 Shaarli Project 1 Shaarli 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php).
CVE-2018-5233 1 Getgrav 1 Grav Cms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/tools.
CVE-2018-5232 1 Atlassian 2 Jira, Jira Server 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.10.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuetype parameter.
CVE-2018-5230 1 Atlassian 2 Jira, Jira Server 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the error message of custom fields when an invalid value is specified.
CVE-2018-5229 1 Atlassian 1 Universal Plugin Manager 2024-11-21 3.5 LOW 5.4 MEDIUM
The NotificationRepresentationFactoryImpl class in Atlassian Universal Plugin Manager before version 2.22.9 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of user submitted add-on names.
CVE-2018-5228 1 Atlassian 2 Crucible, Fisheye 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The /browse/~raw resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the handling of response headers.
CVE-2018-5227 1 Atlassian 1 Application Links 2024-11-21 3.5 LOW 4.8 MEDIUM
Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attackers with administration rights to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the display url of a configured application link.
CVE-2018-5216 1 Radiantcms 1 Radiant Cms 2024-11-21 3.5 LOW 5.4 MEDIUM
Radiant CMS 1.1.4 has XSS via crafted Markdown input in the part_body_content parameter to an admin/pages/*/edit resource.
CVE-2018-5215 1 Fork-cms 1 Fork Cms 2024-11-21 3.5 LOW 5.4 MEDIUM
Fork CMS 5.0.7 has XSS in /private/en/pages/edit via the title parameter.
CVE-2018-5214 1 Add Link To Facebook Project 1 Add Link To Facebook 2024-11-21 3.5 LOW 5.4 MEDIUM
The "Add Link to Facebook" plugin through 2.3 for WordPress has XSS via the al2fb_facebook_id parameter to wp-admin/profile.php.
CVE-2018-5213 1 Simple Download Monitor Project 1 Simple Download Monitor 2024-11-21 3.5 LOW 5.4 MEDIUM
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php.
CVE-2018-5212 1 Simple Download Monitor Project 1 Simple Download Monitor 2024-11-21 3.5 LOW 5.4 MEDIUM
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php.