Vulnerabilities (CVE)

Filtered by CWE-79
Angry Yack Logo
Total 42233 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-18219 1 Sitemagic 1 Sitemagic 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input. The affected components (index.php, upgrade.php) allow for JavaScript injection within both GET or POST requests, via a crafted URL or via the UpgradeMode POST parameter.
CVE-2019-18210 1 Moodle 1 Moodle 2024-11-21 3.5 LOW 5.4 MEDIUM
Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject JavaScript into the session of another user (e.g., enrolled student or site administrator) via the introeditor[text] parameter. NOTE: the discoverer and vendor disagree on whether Moodle customers have a reasonable expectation that anyone authenticated as a Teacher can be trusted with the ability to add arbitrary JavaScript (this ability is not documented on Moodle's Teacher_rol ...

Show More

CVE-2019-18209 1 Etherpad 1 Etherpad 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
CVE-2019-18207 1 Zucchetti 1 Infobusiness 2024-11-21 3.5 LOW 5.4 MEDIUM
In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper validation of the Title field in the InfoBusiness Web Component. The payload will be triggered every time a user browses the reports page.
CVE-2019-18205 1 Zucchetti 1 Infobusiness 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did not properly sanitize user input (encoded in base64). This also applies to the search functionality for the searchKey parameter.
CVE-2019-18203 1 Ricoh 2 Mp 501, Mp 501 Firmware 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
On the RICOH MP 501 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn and KeyDisplay parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
CVE-2019-17674 2 Debian, Wordpress 2 Debian Linux, Wordpress 2024-11-21 3.5 LOW 5.4 MEDIUM
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
CVE-2019-17672 2 Debian, Wordpress 2 Debian Linux, Wordpress 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
CVE-2019-17663 2 D-link, Dlink 2 Dir-866l Firmware, Dir-866l 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
D-Link DIR-866L 1.03B04 devices allow XSS via HtmlResponseMessage in the device common gateway interface, leading to common injection.
CVE-2019-17660 1 Limesurvey 1 Limesurvey 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in admin/translate/translateheader_view.php in LimeSurvey 3.19.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the tolang parameter, as demonstrated by the index.php/admin/translate/sa/index/surveyid/336819/lang/ PATH_INFO.
CVE-2019-17651 1 Fortinet 1 Fortisiem 2024-11-21 3.5 LOW 5.4 MEDIUM
An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5 and below may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious JavaScript code into the description field of a Device Maintenance schedule.
CVE-2019-17634 1 Eclipse 1 Memory Analyzer 2024-11-21 8.5 HIGH 9.0 CRITICAL
Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a cross site scripting (XSS) vulnerability when generating an HTML report from a malicious heap dump. The user must chose todownload, open the malicious heap dump and generate an HTML report for the problem to occur. The heap dump could be specially crafted, or could come from a crafted application or from an application processing malicious data. The vulnerability is present whena report is generated and opened from the Memory Anal ...

Show More

CVE-2019-17632 1 Eclipse 1 Jetty 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.
CVE-2019-17630 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 3.5 LOW 4.8 MEDIUM
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen.
CVE-2019-17629 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 3.5 LOW 4.8 MEDIUM
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen.
CVE-2019-17625 1 Rambox 1 Rambox 2024-11-21 8.5 HIGH 9.0 CRITICAL
There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for Node.js and Electron, such as an exec of OS commands within the onerror attribute of an IMG element.
CVE-2019-17611 1 Hongcms Project 1 Hongcms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
HongCMS 3.0.0 has XSS via the install/index.php tableprefix parameter.
CVE-2019-17610 1 Hongcms Project 1 Hongcms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
HongCMS 3.0.0 has XSS via the install/index.php dbpassword parameter.
CVE-2019-17609 1 Hongcms Project 1 Hongcms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
HongCMS 3.0.0 has XSS via the install/index.php dbusername parameter.
CVE-2019-17608 1 Hongcms Project 1 Hongcms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
HongCMS 3.0.0 has XSS via the install/index.php dbname parameter.
CVE-2019-17607 1 Hongcms Project 1 Hongcms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
HongCMS 3.0.0 has XSS via the install/index.php servername parameter.
CVE-2019-17606 1 Hexo-admin Project 1 Hexo-admin 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.
CVE-2019-17599 1 Expresstech 1 Quiz And Survey Master 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The component is: admin/quiz-options-page.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.
CVE-2019-17581 1 Dormsystem Project 1 Dormsystem 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
tonyy dormsystem through 1.3 allows DOM XSS.
CVE-2019-17579 1 Sonarsource 1 Sonarqube 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SonarSource SonarQube before 7.8 has XSS in project links on account/projects.
CVE-2019-17578 1 Dolibarr 1 Dolibarr Erp\/crm 2024-11-21 3.5 LOW 5.4 MEDIUM
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field.
CVE-2019-17577 1 Dolibarr 1 Dolibarr Erp\/crm 2024-11-21 3.5 LOW 5.4 MEDIUM
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field.
CVE-2019-17576 1 Dolibarr 1 Dolibarr Erp\/crm 2024-11-21 3.5 LOW 5.4 MEDIUM
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field.
CVE-2019-17573 2 Apache, Oracle 7 Cxf, Commerce Guided Search, Communications Element Manager and 4 more 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in modern browsers, who remove dot segments before sending the request. However, Mobile applications may be vulnerable.
CVE-2019-17557 1 Apache 1 Syncope 2024-11-21 3.5 LOW 5.4 MEDIUM
It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user accessing the Enduser UI could execute javascript code from URL query string.
CVE-2019-17551 1 Apakgroup 1 Wholesale Floorplanning Finance 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In Apak Wholesale Floorplanning Finance 6.31.8.3 and 6.31.8.5, an attacker can send an authenticated POST request with a malicious payload to /WFS/agreementView.faces allowing a stored XSS via the mainForm:loanNotesnotes:0:rich_text_editor_note_text parameter in the Notes section. Although versions 6.31.8.3 and 6.31.8.5 are confirmed to be affected, all versions with the vulnerable WYSIWYG editor in the Notes section are likely affected.
CVE-2019-17550 1 Adenion 1 Blog2social 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the b2s_id parameter. The component is: views/b2s/post.calendar.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.
CVE-2019-17535 1 Gilacms 1 Gila Cms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Gila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a related issue to CVE-2019-9647.
CVE-2019-17524 1 Technicolor 2 Tc7300.b0, Tc7300.b0 Firmware 2024-11-21 3.5 LOW 5.4 MEDIUM
An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the "Connected Clients" field to /wlanAccess.asp. An intranet host can use a crafted hostname to exploit this.
CVE-2019-17523 1 Technicolor 2 Tc7300.b0, Tc7300.b0 Firmware 2024-11-21 3.5 LOW 5.4 MEDIUM
An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the FileName parameter to /FTPDiag.asp.
CVE-2019-17522 1 Hotarucms 1 Hotarucms 2024-11-21 3.5 LOW 4.8 MEDIUM
A stored XSS vulnerability was discovered in Hotaru CMS v1.7.2 via the admin_index.php?page=settings SITE NAME field (aka SITE_NAME), a related issue to CVE-2011-4709.1.
CVE-2019-17515 1 Cleantalk 1 Spam Protection\, Antispam\, Firewall 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and inc/cleantalk-comments.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.
CVE-2019-17504 1 Kirona 1 Dynamic Resource Scheduling 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script via the /osm/report/ password parameter.
CVE-2019-17496 1 Craftcms 1 Craft Cms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
CVE-2019-17494 1 Laravel-bjyblog Project 1 Laravel-bjyblog 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
laravel-bjyblog 6.1.1 has XSS via a crafted URL.