VulnSea

CWE-79

CVEs classified under CWE-79, newest first.

2144 CVEsRSS

CVE-2021-36212Medium· 6.1
5y ago

app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.

app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view.

▾ Sunlitmisp-project · mispEPSS 0.63%via NVD
CVE-2021-31721Medium· 6.1
5y ago

Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage.

Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage.

▾ Sunlitchevereto · cheveretoEPSS 0.89%via NVD
CVE-2020-26801Medium· 5.4
5y ago

A stored cross-site scripting (XSS) vulnerability was discovered in /Forms/device_vars_1 on TrippLite SU2200RTXL2Ua with firmware version 12.04.0055

A stored cross-site scripting (XSS) vulnerability was discovered in /Forms/device_vars_1 on TrippLite SU2200RTXL2Ua with firmware version 12.04.0055. This vulnerability allows authenticated attackers to obtain other users' information vi…

▾ Sunlittripplite · su2200rtxl2ua_firmwareEPSS 0.52%via NVD
CVE-2020-19511Medium· 6.1
5y ago

Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,

Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,

▾ Sunlittypesettercms · typesetterEPSS 0.83%via NVD
CVE-2020-21517Medium· 6.1
5y ago

Cross Site Scripting (XSS) vulnerability in MetInfo 7.0.0 via the gourl parameter in login.php.

Cross Site Scripting (XSS) vulnerability in MetInfo 7.0.0 via the gourl parameter in login.php.

▾ Sunlitmetinfo · metinfoEPSS 0.95%via NVD
CVE-2021-29049Medium· 6.1
5y ago

Cross-site scripting (XSS) vulnerability in the Portal Workflow module's edit process page in Liferay DXP 7.0 before fix pack 99, 7.1 before fix pack 23, 7.2 before fix pack 12 and 7.3 before fix pack 1, allows remote attackers to inject…

Cross-site scripting (XSS) vulnerability in the Portal Workflow module's edit process page in Liferay DXP 7.0 before fix pack 99, 7.1 before fix pack 23, 7.2 before fix pack 12 and 7.3 before fix pack 1, allows remote attackers to inject…

▾ Sunlitliferay · digital_experience_platformEPSS 0.75%via NVD
CVE-2020-26680Medium· 5.4
5y ago

In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload

In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentio…

▾ Sunlitvfairs · vfairsEPSS 0.46%via NVD
CVE-2021-27676Medium· 5.4
5y ago

Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability

Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Description) and dep_name (Dependency Name) parameters are vulnerable to stored XSS. A user has to log in and go to the C…

▾ Sunlitcentreon · centreonEPSS 0.62%via NVD
CVE-2021-33425Medium· 5.4
5y ago

A stored cross-site scripting (XSS) vulnerability was discovered in the Web Interface for OpenWRT LuCI version 19.07 which allows attackers to inject arbitrary Javascript in the OpenWRT Hostname via the Hostname Change operation.

A stored cross-site scripting (XSS) vulnerability was discovered in the Web Interface for OpenWRT LuCI version 19.07 which allows attackers to inject arbitrary Javascript in the OpenWRT Hostname via the Hostname Change operation.

▾ Sunlitopenwrt · openwrtEPSS 0.51%via NVD
CVE-2021-27821Medium· 6.1
5y ago

The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability which can lead to attackers carrying out arbitrary code execution.

The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability which can lead to attackers carrying out arbitrary code execution.

▾ Sunlitopenwrt · luciEPSS 0.59%via NVD
CVE-2017-17678Medium· 6.1
5y ago

BMC Remedy Mid Tier 9.1SP3 is affected by cross-site scripting (XSS)

BMC Remedy Mid Tier 9.1SP3 is affected by cross-site scripting (XSS). A DOM-based cross-site scripting vulnerability was discovered in a legacy utility.

▾ Sunlitbmc · remedy_mid-tierEPSS 0.59%via NVD
CVE-2021-29048Medium· 6.1
5y ago

Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.2 before fix pack 11 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web scri…

Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.2 before fix pack 11 and 7.3 before fix pack 1 allows remote attackers to inject arbitrary web scri…

▾ Sunlitliferay · digital_experience_platformEPSS 0.87%via NVD
CVE-2021-29046Medium· 6.1
5y ago

Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1, allows remote attackers to inject arbitrary web script or HTML via the _com_lifer…

Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1, allows remote attackers to inject arbitrary web script or HTML via the _com_lifer…

▾ Sunlitliferay · dxpEPSS 0.88%via NVD
CVE-2021-29051Medium· 6.1
5y ago

Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal 7.2.1 through 7.3.5, and Liferay DXP 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 allows remote attackers to…

Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal 7.2.1 through 7.3.5, and Liferay DXP 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 allows remote attackers to…

▾ Sunlitliferay · digital_experience_platformEPSS 0.75%via NVD
CVE-2021-29045Medium· 6.1
5y ago

Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML…

Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML…

▾ Sunlitliferay · dxpEPSS 0.80%via NVD
CVE-2021-29044Medium· 6.1
5y ago

Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 b…

Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 b…

▾ Sunlitliferay · digital_experience_platformEPSS 0.75%via NVD
CVE-2021-29039Medium· 6.1
5y ago

Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inject arbitrary web script or HTML via the site name.

Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inject arbitrary web script or HTML via the site name.

▾ Sunlitliferay · liferay_portalEPSS 0.75%via NVD
CVE-2021-25680Medium· 6.1PoC
5y ago

The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues

The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not …

▾ Twilightadtran · personal_phone_managerEPSS 2.5%via NVD
CVE-2021-25679Medium· 5.4PoC
5y ago

The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues

The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have…

▾ Twilightadtran · personal_phone_managerEPSS 2.7%via NVD
CVE-2021-30109Medium· 6.1PoC
5y ago

Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS)

Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads to persistent Cross-site scripting (XSS) vulnerability within the hyperlink creation module.

▾ Twilightfroala · froala_editorEPSS 1.2%via NVD
CVE-2021-27695Medium· 6.1PoC
5y ago

Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Par…

Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any "Add" sections, such as Add Card Building & Floor, or others in the Name and Code Par…

▾ Twilightopenmaint · openmaintEPSS 3.0%via NVD
CVE-2020-27576Medium· 5.4
5y ago

Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site scripting (XSS)

Maxum Rumpus 8.2.13 and 8.2.14 is affected by cross-site scripting (XSS). Users are able to create folders in the web application. The folder name is insufficiently validated resulting in a stored cross-site scripting vulnerability.

▾ Sunlitmaxum · rumpusEPSS 0.56%via NVD
CVE-2020-24912Medium· 6.1PoC
5y ago

A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.

A reflected cross-site scripting (XSS) vulnerability in qcubed (all versions including 3.1.1) in profile.php via the stQuery-parameter allows unauthenticated attackers to steal sessions of authenticated users.

▾ Twilightqcubed · qcubedEPSS 6.3%via NVD
CVE-2021-25299Medium· 6.1PoC
5y ago

Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS)

Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when …

▾ Twilightnagios · nagios_xiEPSS 98%via NVD
CVE-2021-3294Medium· 5.4PoC
5y ago

CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php

CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a cookie to perform user redirection to a malicious website.

▾ Twilightcasap_automated_enrollment_system_project · casap_automated_enrollment_systemEPSS 2.8%via NVD
CVE-2020-36012Medium· 4.8
5y ago

Stored XSS vulnerability in BDTASK Multi-Store Inventory Management System 1.0 allows a local admin to inject arbitrary code via the Customer Name Field.

Stored XSS vulnerability in BDTASK Multi-Store Inventory Management System 1.0 allows a local admin to inject arbitrary code via the Customer Name Field.

▾ Sunlitbdtask · multi-storeEPSS 0.56%via NVD
CVE-2020-35854Medium· 4.8
5y ago

Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.

Textpattern 4.8.4 is affected by cross-site scripting (XSS) in the Body parameter.

▾ Sunlittextpattern · textpatternEPSS 0.57%via NVD
CVE-2020-36011Medium· 4.8
5y ago

A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbitrary code via the Name, Guardian Name, Email, Address, Remarks, or Any Known Allergies field.

A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbitrary code via the Name, Guardian Name, Email, Address, Remarks, or Any Known Allergies field.

▾ Sunlitqdocs · smart_hospitalEPSS 0.70%via NVD
CVE-2020-24085Medium· 6.1
5y ago

A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function

A cross-site scripting (XSS) vulnerability exists in MISP v2.4.128 in app/Controller/UserSettingsController.php at SetHomePage() function. Due to a lack of controller validation in "path" parameter, an attacker can execute malicious Java…

▾ Sunlitmisp-project · mispEPSS 0.83%via NVD
CVE-2020-28707Medium· 6.1
5y ago

The Stockdio Historical Chart plugin before 2.8.1 for WordPress is affected by Cross Site Scripting (XSS) via stockdio_chart_historical-wp.js in wp-content/plugins/stockdio-historical-chart/assets/ because the origin of a postMessage() e…

The Stockdio Historical Chart plugin before 2.8.1 for WordPress is affected by Cross Site Scripting (XSS) via stockdio_chart_historical-wp.js in wp-content/plugins/stockdio-historical-chart/assets/ because the origin of a postMessage() e…

▾ Sunlitstockdio · stockdio_historical_chartEPSS 1.0%via NVD
CWE-79 vulnerabilities (CVEs) — page 69 · VulnSea