Total
36870 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-16728 | 1 Feindura | 1 Feindura | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
feindura 2.0.7 allows XSS via the tags field of a new page created at index.php?category=0&page=new. | |||||
CVE-2018-16727 | 1 Razorcms | 1 Razorcms | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component. | |||||
CVE-2018-16726 | 1 Razorcms | 1 Razorcms | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component. | |||||
CVE-2018-16725 | 1 Baijiacms Project | 1 Baijiacms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue is discovered in baijiacms V4. XSS exists via the assets/weengine/components/zclip/ZeroClipboard.swf id parameter, aka "Non-standard use of the flash component." | |||||
CVE-2018-16718 | 1 Nih | 1 Ncbi Toolbox | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted -z1 argument. | |||||
CVE-2018-16655 | 1 Gxlcms | 1 Gxlcms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php. | |||||
CVE-2018-16654 | 1 Zurmo | 1 Zurmo Crm | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Zurmo 3.2.4 Stable allows XSS via app/index.php/accounts/default/details?id=2&kanbanBoard=1&openToTaskId=1. | |||||
CVE-2018-16653 | 1 Rejucms Project | 1 Rejucms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
rejucms 2.1 has XSS via the ucenter/cms_user_add.php u_name parameter. | |||||
CVE-2018-16639 | 1 Typesettercms | 1 Typesetter | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation. | |||||
CVE-2018-16638 | 1 Modx | 1 Evolution Cms | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Evolution CMS 1.4.x allows XSS via the manager/ search parameter. | |||||
CVE-2018-16637 | 1 Modx | 1 Evolution Cms | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI. | |||||
CVE-2018-16636 | 1 Nucleuscms | 1 Nucleus Cms | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
Nucleus CMS 3.70 allows HTML Injection via the index.php body parameter. | |||||
CVE-2018-16635 | 1 Blackcat-cms | 1 Blackcat Cms | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php. | |||||
CVE-2018-16633 | 1 Pluck-cms | 1 Pluck | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title. | |||||
CVE-2018-16632 | 1 Jupo | 1 Mezzanine | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
Mezzanine CMS v4.3.1 allows XSS via the /admin/blog/blogcategory/add/?_to_field=id&_popup=1 title parameter at admin/blog/blogpost/add/. | |||||
CVE-2018-16631 | 1 Intelliants | 1 Subrion Cms | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter. | |||||
CVE-2018-16630 | 1 Getkirby | 1 Kirby | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
Kirby v2.5.12 allows XSS by using the "site files" Add option to upload an SVG file. | |||||
CVE-2018-16629 | 1 Intelliants | 1 Subrion Cms | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element. | |||||
CVE-2018-16628 | 1 Getkirby | 1 Kirby | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
panel/login in Kirby v2.5.12 allows XSS via a blog name. | |||||
CVE-2018-16626 | 1 Typesettercms | 1 Typesetter | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name. |