CVE-2019-10219Medium· 6.1▾ TwilightPoC availableA vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS a…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 33.6 · likelihood 0.4 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 21.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.2%
2 GitHub repos
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
hibernate_validator < 6.0.18hibernate_validator = 6.1.0fuse = 1.0jboss_data_gridjboss_enterprise_application_platformopenshift_application_runtimessingle_sign-onjboss_enterprise_application_platform = 7.2jboss_enterprise_application_platform = 7.3active_iq_unified_managermanagement_services_for_element_software_and_netapp_hcisnapcenter_plug-inelementaccess_manager = 11.1.2.3.0access_manager = 12.2.1.3.0access_manager = 12.2.1.4.0agile_engineering_data_management = 6.2.1.0agile_plm = 9.3.3agile_plm = 9.3.6agile_product_lifecycle_analytics = 3.6.1agile_product_lifecycle_management_integration_pack = 3.6airlines_data_model = 12.1.1.0.0airlines_data_model = 12.2.0.1.0application_express = 21.1.4application_performance_management = 13.4.1.0application_performance_management = 13.5.1.0application_testing_suite = 13.3.0.1argus_analytics = 8.2.1argus_analytics = 8.2.2argus_analytics = 8.2.3argus_analytics = 8.21argus_insight = 8.2.1argus_insight = 8.2.2argus_insight = 8.2.3argus_safety = 8.2.1argus_safety = 8.2.2argus_safety = 8.2.3banking_apis = 18.1banking_apis = 18.2banking_apis = 18.3banking_apis = 19.1banking_apis = 19.2banking_apis = 20.1banking_apis = 21.1banking_deposits_and_lines_of_credit_servicing = 2.12.0banking_digital_experience = 17.2banking_digital_experience = 18.1banking_digital_experience = 18.3banking_digital_experience = 19.1banking_digital_experience = 19.2banking_digital_experience = 20.1banking_digital_experience = 21.1banking_enterprise_default_management = 2.6.2banking_enterprise_default_management = 2.7.0banking_enterprise_default_management = 2.7.1banking_enterprise_default_management = 2.10.0banking_enterprise_default_management = 2.12.0banking_enterprise_default_managment >= 2.3.0, <= 2.4.0banking_loans_servicing = 2.12.0banking_party_management = 2.7.0banking_platform >= 2.3.0, <= 2.4.1banking_platform = 2.6.2banking_platform = 2.7.0banking_platform = 2.7.1bi_publisher = 5.5.0.0.0bi_publisher = 11.1.1.9.0bi_publisher = 12.2.1.3.0bi_publisher = 12.2.1.4.0big_data_spatial_and_graph = 23.1business_activity_monitoring = 12.2.1.4.0business_intelligence = 5.5.0.0.0business_intelligence = 5.9.0.0.0business_intelligence = 12.2.1.3.0business_intelligence = 12.2.1.4.0business_process_management_suite = 12.2.1.3.0business_process_management_suite = 12.2.1.4.0clinical = 5.2.1clinical = 5.2.2commerce_guided_search = 11.3.2commerce_platform >= 11.3.0, <= 11.3.2communications_application_session_controller = 3.9.0communications_billing_and_revenue_management = 12.0.0.3communications_billing_and_revenue_management = 12.0.0.4communications_billing_and_revenue_management_elastic_charging_engine = 11.3communications_billing_and_revenue_management_elastic_charging_engine = 12.0communications_calendar_server = 8.0.0.5.0communications_calendar_server = 8.0.0.6.0communications_cloud_native_core_automated_test_suite = 1.8.0communications_cloud_native_core_binding_support_function = 1.9.0communications_cloud_native_core_binding_support_function = 1.10.0communications_cloud_native_core_console = 1.7.0communications_cloud_native_core_network_function_cloud_native_environment = 1.9.0communications_cloud_native_core_network_repository_function = 1.14.0communications_cloud_native_core_policy = 1.14.0communications_cloud_native_core_security_edge_protection_proxy = 1.5.0communications_cloud_native_core_security_edge_protection_proxy = 1.6.0communications_cloud_native_core_security_edge_protection_proxy = 1.15.0communications_cloud_native_core_service_communication_proxy = 1.14.0communications_cloud_native_core_unified_data_repository = 1.14.0communications_contacts_server = 8.0.0.3.0Upgrade past the affected range:
hibernate_validator 6.0.18Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2020-3580Medium· 6.1Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting …
CVE-2018-6882Medium· 6.1Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTM…
CVE-2025-23366Medium· 6.5A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users
CVE-2019-1973Medium· 4.8A vulnerability in the web portal framework of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface
CVE-2020-1106Medium· 6.1A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server
CVE-2020-1101Medium· 5.4A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server