Vulnerabilities (CVE)

Filtered by CWE-79
Angry Yack Logo
Total 42233 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-28919 1 Checkmk 1 Checkmk 2024-11-21 3.5 LOW 5.4 MEDIUM
A stored cross site scripting (XSS) vulnerability in Checkmk 1.6.0x prior to 1.6.0p19 allows an authenticated remote attacker to inject arbitrary JavaScript via a javascript: URL in a view title.
CVE-2020-28903 1 Nagios 1 Fusion 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS.
CVE-2020-28859 1 Openasset 1 Digital Asset Management 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for reflected cross-site scripting attacks.
CVE-2020-28857 1 Openasset 1 Digital Asset Management 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
OpenAsset Digital Asset Management (DAM) through 12.0.19, does not correctly sanitize user supplied input in multiple parameters and endpoints, allowing for stored cross-site scripting attacks.
CVE-2020-28849 1 Churchcrm 1 Churchcrm 2024-11-21 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in ChurchCRM version 4.2.1, allows remote attckers to execute arbitrary code and gain sensitive information via crafted payload in Add New Deposit field in View All Deposit module.
CVE-2020-28847 1 Valine.js 1 Valine 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in xCss Valine v1.4.14 via the nick parameter to /classes/Comment.
CVE-2020-28727 1 Seeddms 1 Seeddms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChooser.php.
CVE-2020-28722 1 Deskpro 1 Deskpro 2024-11-21 3.5 LOW 5.4 MEDIUM
Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templates.
CVE-2020-28717 1 Kindsoft 1 Kindeditor 2024-11-21 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in content1 parameter in demo.jsp in kindsoft kindeditor version 4.1.12, allows attackers to execute arbitrary code.
CVE-2020-28707 1 Stockdio 1 Stockdio Historical Chart 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Stockdio Historical Chart plugin before 2.8.1 for WordPress is affected by Cross Site Scripting (XSS) via stockdio_chart_historical-wp.js in wp-content/plugins/stockdio-historical-chart/assets/ because the origin of a postMessage() event is not validated. The stockdio_eventer function listens for any postMessage event. After a message event is sent to the application, this function sets the "e" variable as the event and checks that the types of the data and data.method are not undefined (emp ...

Show More

CVE-2020-28650 1 Wpbakery 1 Page Builder 2024-11-21 3.5 LOW 6.4 MEDIUM
The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard WordPress XSS protection mechanism for the Author and Contributor roles.
CVE-2020-28647 1 Progress 1 Moveit Transfer 2024-11-21 3.5 LOW 5.4 MEDIUM
In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser (XSS).
CVE-2020-28487 1 Visjs 1 Vis-timeline 2024-11-21 6.0 MEDIUM 6.8 MEDIUM
This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application.
CVE-2020-28470 1 Scully 1 Scully 2024-11-21 4.3 MEDIUM 7.3 HIGH
This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.
CVE-2020-28459 1 Markdown-it-decorate Project 1 Markdown-it-decorate 2024-11-21 N/A 7.3 HIGH
This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.
CVE-2020-28457 1 S-cart 1 S-cart 2024-11-21 3.5 LOW 7.2 HIGH
This affects the package s-cart/core before 4.4. The search functionality of the admin dashboard in core/src/Admin/Controllers/AdminOrderController.phpindex is vulnerable to XSS.
CVE-2020-28456 1 S-cart 1 S-cart 2024-11-21 4.3 MEDIUM 7.3 HIGH
The package s-cart/core before 4.4 are vulnerable to Cross-site Scripting (XSS) via the admin panel.
CVE-2020-28455 1 Markdown-it-toc Project 1 Markdown-it-toc 2024-11-21 N/A 7.3 HIGH
This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.
CVE-2020-28415 1 Tranzware Payment Gateway Project 1 Tranzware Payment Gateway 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauthenticated attacker is able to execute arbitrary HTML code via crafted url (different vector than CVE-2020-28414).
CVE-2020-28414 1 Tranzware Payment Gateway Project 1 Tranzware Payment Gateway 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauthenticated attacker is able to execute arbitrary HTML code via crafted url (different vector than CVE-2020-28415).
CVE-2020-28409 1 Dundas 1 Dundas Bi 2024-11-21 3.5 LOW 5.4 MEDIUM
The server in Dundas BI through 8.0.0.1001 allows XSS via addition of a Component (e.g., a button) when events such as click, hover, etc. occur.
CVE-2020-28408 1 Dundas 1 Dundas Bi 2024-11-21 3.5 LOW 5.4 MEDIUM
The server in Dundas BI through 8.0.0.1001 allows XSS via an HTML label when creating or editing a dashboard.
CVE-2020-28365 1 Sapplica 1 Sentrifugo 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Sentrifugo 3.2 allows Stored Cross-Site Scripting (XSS) vulnerability by inserting a payload within the X-Forwarded-For HTTP header during the login process. When an administrator looks at logs, the payload is executed. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2020-28364 1 Locust 1 Locust 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability affects the Web UI in Locust before 1.3.2, if the installation violates the usage expectations by exposing this UI to outside users.
CVE-2020-28351 1 Mitel 2 Shoretel, Shoretel Firmware 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack (via the PATH_INFO to index.php) due to insufficient validation for the time_zone object in the HOME_MEETING& page.
CVE-2020-28350 1 Sokrates 1 Sowasql 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A Cross Site Scripting (XSS) vulnerability exists in OPAC in Sokrates SOWA SowaSQL through 5.6.1 via the sowacgi.php typ parameter.
CVE-2020-28249 1 Joplin Project 1 Joplin 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Joplin 1.2.6 for Desktop allows XSS via a LINK element in a note.
CVE-2020-28210 1 Schneider-electric 1 Ecostruxure Building Operation 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability exists in EcoStruxure Building Operation WebStation V2.0 - V3.1 that could cause an attacker to inject HTML and JavaScript code into the user's browser.
CVE-2020-28184 1 Terra-master 1 Tos 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in TerraMaster TOS <= 4.2.06 allows remote authenticated users to inject arbitrary web script or HTML via the mod parameter to /module/index.php.
CVE-2020-28149 1 Mydbr 1 Mydbr 2024-11-21 6.8 MEDIUM 9.6 CRITICAL
myDBR 5.8.3/4262 is affected by: Cross Site Scripting (XSS). The impact is: execute arbitrary code (remote). The component is: CSRF Token. The attack vector is: CSRF token injection to XSS.
CVE-2020-28146 1 Eyoucms 1 Eyoucms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter.
CVE-2020-28141 1 Online Discussion Forum Project 1 Online Discussion Forum 2024-11-21 3.5 LOW 5.4 MEDIUM
The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated user can send messages to arbitrary users on the system that include javascript that will execute when viewing the messages page.
CVE-2020-28139 1 Online Clothing Store Project 1 Online Clothing Store 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SourceCodester Online Clothing Store 1.0 is affected by a cross-site scripting (XSS) vulnerability via a Offer Detail field in offer.php.
CVE-2020-28124 1 Lavalite 1 Lavalite 2024-11-21 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) in LavaLite 5.8.0 via the Address field.
CVE-2020-28119 1 53kf 1 53kf 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross site scripting vulnerability in 53KF < 2.0.0.2 that allows for arbitrary code to be executed via crafted HTML statement inserted into chat window.
CVE-2020-28092 1 Pescms 1 Pescms Team 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&m=Task&a=my&status=1&id=,?g=Team&m=Task&a=my&status=10&id=
CVE-2020-28071 1 Alumni Management System Project 1 Alumni Management System 2024-11-21 3.5 LOW 4.8 MEDIUM
SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored XSS.
CVE-2020-28047 1 Web-audimex 1 Audimexee 2024-11-21 3.5 LOW 5.4 MEDIUM
AudimexEE before 14.1.1 is vulnerable to Reflected XSS (Cross-Site-Scripting). If the recommended security configuration parameter "unique_error_numbers" is not set, remote attackers can inject arbitrary web script or HTML via 'action, cargo, panel' parameters that can lead to data leakage.
CVE-2020-28038 3 Debian, Fedoraproject, Wordpress 3 Debian Linux, Fedora, Wordpress 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
WordPress before 5.5.2 allows stored XSS via post slugs.
CVE-2020-28034 3 Debian, Fedoraproject, Wordpress 3 Debian Linux, Fedora, Wordpress 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
WordPress before 5.5.2 allows XSS associated with global variables.