Vulnerabilities (CVE)

Filtered by CWE-79
Angry Yack Logo
Total 42233 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-8812 1 Bludit 1 Bludit 2024-11-21 3.5 LOW 5.4 MEDIUM
Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's perspective is that this is "not a bug.
CVE-2020-8799 1 Webtechideas 1 Wti Like Post 2024-11-21 3.5 LOW 4.8 MEDIUM
A Stored XSS vulnerability has been found in the administration page of the WTI Like Post plugin through 1.4.5 for WordPress. Once the administrator has submitted the data, the script stored is executed for all the users visiting the website.
CVE-2020-8789 1 Composr Project 1 Composr 2024-11-21 3.5 LOW 5.4 MEDIUM
Composr 10.0.30 allows Persistent XSS via a Usergroup name under the Security configuration.
CVE-2020-8788 1 Synaptivemedical 1 Clearcanvas 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Synaptive Medical ClearCanvas ImageServer 3.0 Alpha allows XSS (and HTML injection) via the Default.aspx UserName parameter. NOTE: the issues/227 reference does not imply that the affected product can be downloaded from GitHub. It was simply a convenient location for a public bug report.
CVE-2020-8778 1 Alfresco 1 Alfresco 2024-11-21 3.5 LOW 5.4 MEDIUM
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document, when the attacker has write access to a project.
CVE-2020-8777 1 Alfresco 1 Alfresco 2024-11-21 3.5 LOW 5.4 MEDIUM
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo, as demonstrated by a SCRIPT element in an SVG document.
CVE-2020-8776 1 Alfresco 1 Alfresco 2024-11-21 3.5 LOW 5.4 MEDIUM
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a file.
CVE-2020-8775 1 Pega 1 Platform 2024-11-21 6.0 MEDIUM 8.9 HIGH
Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.
CVE-2020-8774 1 Pega 1 Pega Platform 2024-11-21 6.8 MEDIUM 8.8 HIGH
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.
CVE-2020-8773 1 Pega 1 Platform 2024-11-21 6.0 MEDIUM 8.9 HIGH
The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.
CVE-2020-8723 1 Intel 153 Compute Module Hns2600bp Firmware, Compute Module Hns2600bpb, Compute Module Hns2600bpb24 and 150 more 2024-11-21 5.4 MEDIUM 6.3 MEDIUM
Cross-site scripting for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
CVE-2020-8612 2 Progess, Progress 2 Moveit Transfer, Moveit Transfer 2024-11-21 6.0 MEDIUM 9.0 CRITICAL
In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execute arbitrary code in a victim's browser, aka XSS.
CVE-2020-8603 1 Trendmicro 1 Interscan Web Security Virtual Appliance 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting vulnerability (XSS) in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow a remote attacker to tamper with the web interface of affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
CVE-2020-8594 1 Ninjaforms 1 Ninja Forms 2024-11-21 3.5 LOW 5.4 MEDIUM
The Ninja Forms plugin 3.4.22 for WordPress has Multiple Stored XSS vulnerabilities via ninja_forms[recaptcha_site_key], ninja_forms[recaptcha_secret_key], ninja_forms[recaptcha_lang], or ninja_forms[date_format].
CVE-2020-8549 1 Wpchill 1 Strong Testimonials 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Stored XSS in the Strong Testimonials plugin before 2.40.1 for WordPress can result in an attacker performing malicious actions such as stealing session tokens.
CVE-2020-8548 1 Masscode 1 Masscode 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
massCode 1.0.0-alpha.6 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true).
CVE-2020-8542 1 Open-xchange 1 Open-xchange Appsuite 2024-11-21 3.5 LOW 5.4 MEDIUM
OX App Suite through 7.10.3 allows XSS.
CVE-2020-8514 2 Apple, Maxum 2 Macos, Rumpus 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Rumpus 8.2.10 on macOS. By crafting a directory name, it is possible to activate JavaScript in the context of the web application after invoking the rename folder functionality.
CVE-2020-8512 1 Icewarp 1 Icewarp Server 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.
CVE-2020-8498 1 Gistpress Project 1 Gistpress 2024-11-21 3.5 LOW 5.4 MEDIUM
XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gistpress.php id parameter. This allows an attacker with the WordPress Contributor role to execute arbitrary JavaScript code with the privileges of other users (e.g., ones who have the publish_posts capability).
CVE-2020-8496 1 Kronos 1 Web Time And Attendance 2024-11-21 3.5 LOW 4.8 MEDIUM
In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability by setting the Application Banner input field of the /ApplicationBanner page as an authenticated administrator.
CVE-2020-8493 1 Kronos 1 Web Time And Attendance 2024-11-21 3.5 LOW 4.8 MEDIUM
A stored XSS vulnerability in Kronos Web Time and Attendance (webTA) affects 3.8.x and later 3.x versions before 4.0 via multiple input fields (Login Message, Banner Message, and Password Instructions) of the com.threeis.webta.H261configMenu servlet via an authenticated administrator.
CVE-2020-8477 1 Abb 1 800xa Information Manager 2024-11-21 6.8 MEDIUM 8.8 HIGH
The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.
CVE-2020-8462 1 Trendmicro 1 Interscan Web Security Virtual Appliance 2024-11-21 3.5 LOW 4.8 MEDIUM
A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to tamper with the web interface of the product.
CVE-2020-8436 1 Metagauss 1 Registrationmagic 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
XSS was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress via the rm_form_id, rm_tr, or form_name parameter.
CVE-2020-8426 1 Elementor 1 Website Builder 2024-11-21 3.5 LOW 5.4 MEDIUM
The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user.
CVE-2020-8421 1 Joomla 1 Joomla\! 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Joomla! before 3.9.15. Inadequate escaping of usernames allows XSS attacks in com_actionlogs.
CVE-2020-8348 1 Lenovo 1 Enterprise Network Disk 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's current browser session if a crafted url is visited, possibly through phishing.
CVE-2020-8347 1 Lenovo 1 Enterprise Network Disk 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A reflective cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's browser if a crafted url is visited, possibly through phishing.
CVE-2020-8340 1 Lenovo 15 Flex System Nx360 M5, Flex System X240, Flex System X240 M5 and 12 more 2024-11-21 4.3 MEDIUM 6.3 MEDIUM
A cross-site scripting (XSS) vulnerability was discovered in the legacy IBM and Lenovo System x IMM2 (Integrated Management Module 2), prior to version 5.60, embedded Baseboard Management Controller (BMC) web interface during an internal security review. This vulnerability could allow JavaScript code to be executed in the user's web browser if the user is convinced to visit a crafted URL, possibly through phishing. Successful exploitation requires specific knowledge about the user’s network to b ...

Show More

CVE-2020-8339 1 Ibm 2 Bladecenter Advanced Management Module, Bladecenter Advanced Management Module Firmware 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior to version 3.68n [BPET68N]. This vulnerability could allow an authenticated user's AMM credentials to be disclosed if the user is convinced to visit a malicious web site, possibly through phishing. Successful exploitation requires specific knowledge about the user’s network to be included in the malicious web site. Impact is limited to the normal a ...

Show More

CVE-2020-8294 1 Nextcloud 1 Nextcloud Server 2024-11-21 3.5 LOW 5.4 MEDIUM
A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in markdown format.
CVE-2020-8292 1 Rocket.chat 1 Rocket.chat 2024-11-21 4.3 MEDIUM 5.4 MEDIUM
Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.
CVE-2020-8291 1 Rocket.chat 1 Rocket.chat 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks.
CVE-2020-8288 1 Rocket.chat 1 Rocket.chat 2024-11-21 3.5 LOW 5.4 MEDIUM
The `specializedRendering` function in Rocket.Chat server before 3.9.2 allows a cross-site scripting (XSS) vulnerability by way of the `value` parameter.
CVE-2020-8281 1 Nextcloud 1 Contacts 2024-11-21 3.5 LOW 5.4 MEDIUM
A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform cross-site scripting (XSS) attacks.
CVE-2020-8280 1 Nextcloud 1 Contacts 2024-11-21 3.5 LOW 5.4 MEDIUM
A missing file type check in Nextcloud Contacts 3.4.0 allows a malicious user to upload SVG files as PNG files to perform cross-site scripting (XSS) attacks.
CVE-2020-8264 1 Rubyonrails 1 Rails 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in the context of the local application. This vulnerability is in the Actionable Exceptions middleware.
CVE-2020-8263 1 Pulsesecure 1 Pulse Secure Desktop Client 2024-11-21 3.5 LOW 5.4 MEDIUM
A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) through the CGI file.
CVE-2020-8262 2 Ivanti, Pulsesecure 4 Connect Secure, Policy Secure, Pulse Connect Secure and 1 more 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface.