VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2144 CVEsRSS

CVE-2020-20425Medium· 6.1
4y ago

S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in the search function.

S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in the search function.

▾ Sunlits-cms · s-cmsEPSS 0.66%via NVD
CVE-2021-36450Medium· 6.1PoC
4y ago

Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.

Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.

▾ Twilightverint · workforce_optimizationEPSS 64%via NVD
CVE-2021-26787Medium· 6.1
4y ago

A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion) via the Time-off parameter.

A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion) via the Time-off parameter.

▾ Sunlitgenesys · workforce_managementEPSS 0.73%via NVD
CVE-2018-10228Medium· 6.1
4y ago

Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp parameter to the index.php/admin/themes/sa/t…

Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp parameter to the index.php/admin/themes/sa/t…

▾ Sunlitlimesurvey · limesurveyEPSS 0.81%via NVD
CVE-2020-19611Medium· 6.1
4y ago

Cross Site Scripting (XSS) in redirect module of Racktables version 0.21.2, allows an attacker to inject arbitrary web script or HTML via the op parameter.

Cross Site Scripting (XSS) in redirect module of Racktables version 0.21.2, allows an attacker to inject arbitrary web script or HTML via the op parameter.

▾ Sunlitracktables_project · racktablesEPSS 0.63%via NVD
CVE-2021-43687Medium· 6.1
4y ago

chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.

chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.

▾ Sunlitchamilo · chamiloEPSS 1.2%via NVD
CVE-2021-24713Medium· 4.8
4y ago

The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perfor…

The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perfor…

▾ Sunlitcminds · video_lessons_managerEPSS 0.62%via NVD
CVE-2021-41164High· 8.2
4y ago

CKEditor4 is an open source WYSIWYG HTML editor

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malf…

▾ Twilightckeditor · ckeditorEPSS 1.3%via NVD
CVE-2021-36698Medium· 5.4
4y ago

Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.

Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.

▾ Sunlitartica · pandora_fmsEPSS 0.52%via NVD
CVE-2020-27406Medium· 5.4
4y ago

Cross Site Scripting (XSS) vulnerability in DynPG 4.9.1, allows authenticated attackers to execute arbitrary code via the groupname.

Cross Site Scripting (XSS) vulnerability in DynPG 4.9.1, allows authenticated attackers to execute arbitrary code via the groupname.

▾ Sunlitdynpg · dynpgEPSS 0.76%via NVD
CVE-2021-25878Medium· 6.1
4y ago

AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an admini…

AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an admini…

▾ Sunlityouphptube · youphptubeEPSS 0.86%via NVD
CVE-2021-25876Medium· 6.1
4y ago

AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.

AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.

▾ Sunlityouphptube · youphptubeEPSS 0.87%via NVD
CVE-2021-25875Medium· 6.1
4y ago

AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the searchPhrase parameter which allows a remote attacker to steal administrators' session cookies or perform actions as…

AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the searchPhrase parameter which allows a remote attacker to steal administrators' session cookies or perform actions as…

▾ Sunlityouphptube · youphptubeEPSS 0.87%via NVD
CVE-2021-41184Medium· 6.5PoC
4y ago

jQuery-UI is the official jQuery user interface library

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0.…

▾ Twilightjqueryui · jquery_uiEPSS 41%via NVD
CVE-2021-41183Medium· 6.5
4y ago

jQuery-UI is the official jQuery user interface library

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI …

▾ Sunlitjqueryui · jquery_uiEPSS 8.5%via NVD
CVE-2021-41182Medium· 6.5PoC
4y ago

jQuery-UI is the official jQuery user interface library

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.…

▾ Twilightjqueryui · jquery_uiEPSS 39%via NVD
CVE-2021-35506Medium· 6.1
4y ago

Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or edit action.

Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or edit action.

▾ Sunlitafian · filerunEPSS 0.74%via NVD
CVE-2021-35503Medium· 6.1
4y ago

Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity Logs.

Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity Logs.

▾ Sunlitafian · filerunEPSS 0.74%via NVD
CVE-2020-21228Medium· 6.1
4y ago

JIZHICMS 1.5.1 contains a cross-site scripting (XSS) vulnerability in the component /user/release.html, which allows attackers to arbitrarily add an administrator cookie.

JIZHICMS 1.5.1 contains a cross-site scripting (XSS) vulnerability in the component /user/release.html, which allows attackers to arbitrarily add an administrator cookie.

▾ Sunlitjizhicms · jizhicmsEPSS 0.81%via NVD
CVE-2021-41318Medium· 6.1PoC
5y ago

In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input

In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.

▾ Twilightprogress · whatsup_goldEPSS 5.9%via NVD
CVE-2020-20345Medium· 5.4
5y ago

WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box.

WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box.

▾ Sunlitwtcms_project · wtcmsEPSS 0.55%via NVD
CVE-2021-31655Medium· 6.1
5y ago

Cross Site Scripting (XSS) vulnerability in TRENDnet TV-IP110WN V1.2.2.64 V1.2.2.65 V1.2.2.68 via the profile parameter

Cross Site Scripting (XSS) vulnerability in TRENDnet TV-IP110WN V1.2.2.64 V1.2.2.65 V1.2.2.68 via the profile parameter. in a GET request in view.cgi.

▾ Sunlittrendnet · tv-ip110wn_firmwareEPSS 0.75%via NVD
CVE-2021-37743Medium· 5.4
5y ago

app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.

app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON format.

▾ Sunlitmisp-project · mispEPSS 0.68%via NVD
CVE-2021-37742Medium· 5.4
5y ago

app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.

app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.

▾ Sunlitmisp-project · mispEPSS 0.59%via NVD
CVE-2021-37534Medium· 5.4
5y ago

app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.

app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.

▾ Sunlitmisp-project · mispEPSS 0.51%via NVD
CVE-2021-27332Medium· 6.1
5y ago

Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the class_name parameter to update_class.php.

Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the class_name parameter to update_class.php.

▾ Sunlitcasap_automated_enrollment_system_project · casap_automated_enrollment_systemEPSS 0.84%via NVD
CVE-2021-30119Medium· 5.4⚠ Exploited
5y ago

Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `http…

Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecurely returned in the requested web page and can be used to perform a Cross Site Scripting attack Example request: `http…

▾ Twilightkaseya · vsaEPSS 50%via NVD
CVE-2020-20363Medium· 4.8
5y ago

Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.

Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.

▾ Sunlitpbootcms · pbootcmsEPSS 0.57%via NVD
CVE-2020-20584Medium· 6.1
5y ago

A cross site scripting vulnerability in baigo CMS v4.0-beta-1 allows attackers to execute arbitrary web scripts or HTML via the form parameter post to /public/console/profile/info-submit/.

A cross site scripting vulnerability in baigo CMS v4.0-beta-1 allows attackers to execute arbitrary web scripts or HTML via the form parameter post to /public/console/profile/info-submit/.

▾ Sunlitbaigo · baigo_cmsEPSS 1.1%via NVD
CVE-2021-35451Medium· 6.1
5y ago

In Teradici PCoIP Management Console-Enterprise 20.07.0, an unauthenticated user can inject arbitrary text into user browser via the Web application.

In Teradici PCoIP Management Console-Enterprise 20.07.0, an unauthenticated user can inject arbitrary text into user browser via the Web application.

▾ Sunlitteradici · pcoip_management_consoleEPSS 0.72%via NVD
CWE-79 vulnerabilities (CVEs) — page 68 · VulnSea