Vulnerabilities (CVE)

Filtered by CWE-79
Angry Yack Logo
Total 42233 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-15586 1 Gitlab 1 Gitlab 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.
CVE-2019-15539 1 Mantisbt 1 Mantisbt 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The proj_doc_edit_page.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed when editing the document's page.
CVE-2019-15532 1 Gchq 1 Cyberchef 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
CVE-2019-15510 1 Zohocorp 1 Manageengine Desktop Central 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role.
CVE-2019-15501 1 Lsoft 1 Listserv 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
CVE-2019-15499 2 Apple, Hackmd 2 Safari, Codimd 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL.
CVE-2019-15492 1 It-novum 1 Openitcockpit 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.
CVE-2019-15489 1 Laracom 1 Laracom 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS.
CVE-2019-15488 1 Igniterealtime 1 Openfire 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
CVE-2019-15487 1 Schoolexperience 1 Department For Education School Experience 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
DfE School Experience before v16333-GA has XSS via a teacher training URL.
CVE-2019-15486 1 Django Js Reverse Project 1 Django Js Reserve 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.
CVE-2019-15485 1 Boltcms 1 Bolt 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.
CVE-2019-15484 1 Boltcms 1 Bolt 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Bolt before 3.6.10 has XSS via an image's alt or title field.
CVE-2019-15483 1 Boltcms 1 Bolt 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.
CVE-2019-15482 1 Selectize-plugin-a11y Project 1 Selectize-plugin-a11y 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
selectize-plugin-a11y before 1.1.0 has XSS via the msg field.
CVE-2019-15481 1 Kimai 1 Kimai 2 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Kimai v2 before 1.1 has XSS via a timesheet description.
CVE-2019-15480 1 Domoticz 1 Domoticz 2024-11-21 3.5 LOW 5.4 MEDIUM
Domoticz 4.10717 has XSS via item.Name.
CVE-2019-15479 1 Status Board Project 1 Status Board 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Status Board 1.1.81 has reflected XSS via dashboard.ts.
CVE-2019-15478 1 Status Board Project 1 Status Board 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Status Board 1.1.81 has reflected XSS via logic.ts.
CVE-2019-15477 1 Jooby 1 Jooby 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Jooby before 1.6.4 has XSS via the default error handler.
CVE-2019-15476 1 Former Project 1 Former 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Former before 4.2.1 has XSS via a checkbox value.
CVE-2019-15331 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
CVE-2019-15328 1 Codection 1 Import Users From Csv With Meta 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
CVE-2019-15327 1 Codection 1 Import Users From Csv With Meta 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
CVE-2019-15317 1 Givewp 1 Givewp 2024-11-21 3.5 LOW 5.4 MEDIUM
The give plugin before 2.4.7 for WordPress has XSS via a donor name.
CVE-2019-15314 1 Tiki 1 Tikiwiki Cms\/groupware 2024-11-21 3.5 LOW 5.4 MEDIUM
tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI.
CVE-2019-15313 1 Zimbra 1 Collaboration Server 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In Zimbra Collaboration before 8.8.15 Patch 1, there is a non-persistent XSS vulnerability.
CVE-2019-15281 1 Cisco 1 Identity Services Engine Software 2024-11-21 3.5 LOW 4.8 MEDIUM
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The attacker must have valid administrator credentials. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit ...

Show More

CVE-2019-15278 1 Cisco 2 Finesse, Unified Contact Center Express 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to bypass authorization and access sensitive information related to the device. The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could exploit this vulnerability by submitting a crafted URL. A successful exploit could allow the attacker to gain unauthorized access to sensitive information.
CVE-2019-15270 1 Cisco 12 Firepower Management Center, Firepower Management Center 1000, Firepower Management Center 1600 and 9 more 2024-11-21 3.5 LOW 5.4 MEDIUM
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow ...

Show More

CVE-2019-15269 1 Cisco 68 Amp 7150, Amp 7150 Firmware, Amp 8150 and 65 more 2024-11-21 3.5 LOW 4.8 MEDIUM
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful expl ...

Show More

CVE-2019-15268 1 Cisco 68 Amp 7150, Amp 7150 Firmware, Amp 8150 and 65 more 2024-11-21 3.5 LOW 4.8 MEDIUM
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful expl ...

Show More

CVE-2019-15233 1 Oldstreetsolutions 1 Live Input Macros 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of the Administrator Session Cookie.
CVE-2019-15230 1 Librenms 1 Librenms 2024-11-21 3.5 LOW 5.4 MEDIUM
LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account.
CVE-2019-15228 1 Thedaylightstudio 1 Fuel Cms 2024-11-21 3.5 LOW 5.4 MEDIUM
FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account but can also impact unauthenticated visitors.
CVE-2019-15227 1 Getflightpath 1 Flightpath 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead to cookie stealing and other malicious actions.
CVE-2019-15127 1 Vanderbilt 1 Redcap 2024-11-21 3.5 LOW 5.4 MEDIUM
REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file.
CVE-2019-15124 1 Mediawiki 1 Mobilefrontend 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affects REL1_31, REL1_32, and REL1_33.
CVE-2019-15120 1 Kunena 1 Kunena 2024-11-21 3.5 LOW 5.4 MEDIUM
The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
CVE-2019-15112 1 Wp-slimstat 1 Slimstat Analytics 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The wp-slimstat plugin before 4.8.1 for WordPress has XSS.