Vulnerabilities (CVE)

Filtered by CWE-79
Total 36870 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-17884 1 Gwolle Guestbook Project 1 Gwolle Guestbook 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via the PATH_INFO to wp-admin/index.php
CVE-2018-17876 1 Web-feet 1 Coaster Cms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A Stored XSS vulnerability has been discovered in the v5.5.0 version of the Coaster CMS product.
CVE-2018-17874 1 Expressionengine 1 Expressionengine 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
ExpressionEngine before 4.3.5 has reflected XSS.
CVE-2018-17868 1 Dasan 2 H660gw, H660gw Firmware 2024-11-21 3.5 LOW 4.8 MEDIUM
DASAN H660GW devices have Stored XSS in the Port Forwarding functionality.
CVE-2018-17866 1 Ultimatemember 1 Ultimate Member 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile & Membership" plugin before 2.0.28 for WordPress allow remote attackers to inject arbitrary web script or HTML via the "Primary button Text" or "Second button text" field.
CVE-2018-17865 1 Sap 1 J2ee Engine 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine 7.01 allows remote attackers to inject arbitrary web script via the wsdlPath parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2018-17862 1 Sap 1 J2ee Engine 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Fiori allows remote attackers to inject arbitrary web script via the sys_jdbc parameter to /TestJDBC_Web/test2. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2018-17861 1 Sap 1 J2ee Engine 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in SAP J2EE Engine/7.01/Portal/EPP allows remote attackers to inject arbitrary web script via the wsdlLib parameter to /ctcprotocol/Protocol. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2018-17849 1 Naviwebs 1 Navigate Cms 2024-11-21 3.5 LOW 5.4 MEDIUM
Navigate CMS 2.8 has Stored XSS via a navigate_upload.php (aka File Upload) request with a multipart/form-data JavaScript payload.
CVE-2018-17835 1 Get-simple 1 Getsimple Cms 2024-11-21 3.5 LOW 4.8 MEDIUM
An issue was discovered in GetSimple CMS 3.3.15. An administrator can insert stored XSS via the admin/settings.php Custom Permalink Structure parameter, which injects the XSS payload into any page created at the admin/pages.php URI.
CVE-2018-17832 1 Wuzhicms 1 Wuzhi Cms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
CVE-2018-17830 1 Redaxo 1 Redaxo 2024-11-21 3.5 LOW 5.4 MEDIUM
The $args variable in addons/mediapool/pages/index.php in REDAXO 5.6.2 is not effectively filtered, because names are not restricted (only values are restricted). The attacker can insert XSS payloads via an index.php?page=mediapool/media&opener_input_field=&args[ substring.
CVE-2018-17790 1 Prospecta 1 Master Data Online 2024-11-21 4.3 MEDIUM 5.4 MEDIUM
Prospecta Master Data Online (MDO) 2.0 has Stored XSS.
CVE-2018-17784 1 Sugarcrm 1 Sugarcrm 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
CVE-2018-17783 1 Mantisbt 1 Mantisbt 2024-11-21 3.5 LOW 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in the Edit Filter page (manage_filter_edit page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name.
CVE-2018-17782 1 Mantisbt 1 Mantisbt 2024-11-21 3.5 LOW 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name.
CVE-2018-17596 1 Zohocorp 1 Manageengine Assetexplorer 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter.
CVE-2018-17595 1 Fork-cms 1 Fork Cms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In the 5.4.0 version of the Fork CMS software, HTML Injection and Stored XSS vulnerabilities were discovered via the /backend/ajax URI.
CVE-2018-17594 1 Airties 2 Air 5443v2, Air 5443v2 Firmware 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
AirTies Air 5443v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
CVE-2018-17593 1 Airties 2 Air 5453, Air 5453 Firmware 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.