Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2018-14493 | 1 Opmantek | 1 Open-audit | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the group name.
|
|||||
| CVE-2018-14486 | 1 Dnnsoftware | 1 Dotnetnuke | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.
|
|||||
| CVE-2018-14481 | 1 Osclass | 1 Osclass | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280.
|
|||||
| CVE-2018-14478 | 1 Coppermine-gallery | 1 Coppermine Photo Gallery | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.
|
|||||
| CVE-2018-14476 | 1 Metalgenix | 1 Genixcms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
GeniXCMS 1.1.5 has XSS via the dbuser or dbhost parameter during step 1 of installation.
|
|||||
| CVE-2018-14430 | 1 Mondula | 1 Multi Step Form | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Mondula Multi Step Form plugin through 1.2.5 for WordPress allows XSS via the fw_data [id][1], fw_data [id][2], fw_data [id][3], fw_data [id][4], or email field of the contact form, exploitable with an fw_send_email action to wp-admin/admin-ajax.php.
|
|||||
| CVE-2018-14425 | 1 Synacor | 1 Zimbra Collaboration Suite | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
There is a Persistent XSS vulnerability in the briefcase component of Synacor Zimbra Collaboration Suite (ZCS) Zimbra Web Client (ZWC) 8.8.8 before 8.8.8 Patch 7 and 8.8.9 before 8.8.9 Patch 1.
|
|||||
| CVE-2018-14422 | 1 Sanscms | 1 Sanscms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
blog/index.php in SansCMS 0.7 has XSS via the q parameter.
|
|||||
| CVE-2018-14419 | 1 Metinfo | 1 Metinfo | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.
|
|||||
| CVE-2018-14415 | 1 Icmsdev | 1 Icms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen.
|
|||||
| CVE-2018-14397 | 1 Cremecrm | 1 Cremecrm | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
An issue was discovered in Creme CRM 1.6.12. The organization creation page is affected by 9 stored cross-site scripting vulnerabilities involving the name, billing_address-address, billing_address-zipcode, billing_address-city, billing_address-department, shipping_address-address, shipping_address-zipcode, shipping_address-city, and shipping_address-department parameters.
|
|||||
| CVE-2018-14396 | 1 Cremecrm | 1 Cremecrm | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
An issue was discovered in Creme CRM 1.6.12. The salesman creation page is affected by 10 stored cross-site scripting vulnerabilities involving the firstname, lastname, billing_address-address, billing_address-zipcode, billing_address-city, billing_address-department, shipping_address-address, shipping_address-zipcode, shipping_address-city, and shipping_address-department parameters.
|
|||||
| CVE-2018-14392 | 1 Mybb | 1 New Threads | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The New Threads plugin before 1.2 for MyBB has XSS.
|
|||||
| CVE-2018-14388 | 1 Joyplus-cms Project | 1 Joyplus-cms | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter.
|
|||||
| CVE-2018-14384 | 1 Seopanel | 1 Seo Panel | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
The Website Manager module in SEO Panel 3.13.0 and earlier is affected by a stored Cross-Site Scripting (XSS) vulnerability, allowing remote authenticated attackers to inject arbitrary web script or HTML via the websites.php name parameter.
|
|||||
| CVE-2018-14382 | 1 Instantcms | 1 Instantcms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
InstantCMS 2.10.1 has /redirect?url= XSS.
|
|||||
| CVE-2018-14380 | 1 Graylog | 1 Graylog | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
|
|||||
| CVE-2018-14082 | 1 Freelancewebdesignerchennai | 1 Job Portal | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
PHP Scripts Mall JOB SITE (aka Job Portal) 3.0.1 has Cross-site Scripting (XSS) via the search bar.
|
|||||
| CVE-2018-14059 | 1 Pimcore | 1 Pimcore | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions.
|
|||||
| CVE-2018-14042 | 1 Getbootstrap | 1 Bootstrap | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
|
|||||
| CVE-2018-14041 | 1 Getbootstrap | 1 Bootstrap | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
|
|||||
| CVE-2018-14040 | 2 Debian, Getbootstrap | 2 Debian Linux, Bootstrap | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
|
|||||
| CVE-2018-14037 | 1 Progress | 1 Kendo Ui | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbitrary JavaScript into the DOM of the WYSIWYG editor because of the editorNS.Serializer toEditableHtml function in kendo.all.min.js. If the victim accesses the editor, the payload gets executed. Furthermore, if the payload is reflected at any other resource that does rely on the sanitisation of the editor itself, the JavaScript payload will be executed in the context of the appli ...
Show More |
|||||
| CVE-2018-14027 | 1 Digisol | 2 Dg-hr-3300, Dg-hr-3300 Firmware | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Digisol Wireless Wifi Home Router HR-3300 allows XSS via the userid or password parameter to the admin login page.
|
|||||
| CVE-2018-14013 | 1 Synacor | 1 Zimbra Collaboration Suite | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.
|
|||||
| CVE-2018-13999 | 1 Catfish-cms | 1 Catfish Cms | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administrator).
|
|||||
| CVE-2018-13998 | 1 Clippercms | 1 Clippercms | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users.
|
|||||
| CVE-2018-13983 | 1 Impresscms | 1 Impresscms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck.php.
|
|||||
| CVE-2018-13879 | 1 Rocket.chat | 1 Rocket.chat | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
A reflected XSS issue was discovered in the registration form in Rocket.Chat before 0.66. When one creates an account, the next step will ask for a username. This field will not save HTML control characters but an error will be displayed that shows the attempted username unescaped via packages/rocketchat-ui-login/client/username/username.js in packages/rocketchat-ui-login/client/username/username.html.
|
|||||
| CVE-2018-13878 | 1 Rocket.chat | 1 Rocket.chat | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An XSS issue was discovered in packages/rocketchat-mentions/Mentions.js in Rocket.Chat before 0.65. The real name of a username is displayed unescaped when the user is mentioned (using the @ symbol) in a channel or private chat. Consequently, it is possible to exfiltrate the secret token of every user and also admins in the channel.
|
|||||
| CVE-2018-13865 | 1 Idreamsoft | 1 Icms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An issue was discovered in idreamsoft iCMS 7.0.9. XSS exists via the callback parameter in a public/api.php uploadpic request, bypassing the iWAF protection mechanism.
|
|||||
| CVE-2018-13849 | 1 Instagram-clone Project | 1 Instagram-clone | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequate XSS protection mechanism based on preg_replace.
|
|||||
| CVE-2018-13832 | 1 Techotronic | 1 All In One Favicon | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via Apple-Text, GIF-Text, ICO-Text, PNG-Text, or JPG-Text.
|
|||||
| CVE-2018-13825 | 2 Broadcom, Ca | 2 Project Portfolio Management, Project Portfolio Management | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Insufficient input validation in the gridExcelExport functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows remote attackers to execute reflected cross-site scripting attacks.
|
|||||
| CVE-2018-13809 | 1 Siemens | 4 Cp 1604, Cp 1604 Firmware, Cp 1616 and 1 more | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated web server of the affected CP devices could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into following a malicious link. User interaction is required for a successful exploitation. At the time of advisory publication no public exploitation of this vulnerability was known.
|
|||||
| CVE-2018-13433 | 1 Boostnote | 1 Boostnote | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Boostnote v0.11.7 allows XSS during highlighting of Markdown text, as demonstrated by an onerror attribute of an IMG element.
|
|||||
| CVE-2018-13423 | 1 Omeka | 1 Omeka | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
admin/themes/default/items/tag-form.php in Omeka before 2.6.1 allows XSS by adding or editing a tag.
|
|||||
| CVE-2018-13422 | 1 Tecnick | 1 Tcexam | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
TCExam before 14.1.2 has XSS via an ff_ or xl_ field.
|
|||||
| CVE-2018-13409 | 1 Jirafeau | 1 Jirafeau | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An issue was discovered in Jirafeau before 3.4.1. The "search file by hash" form is affected by reflected XSS that could allow, by targeting an administrator, stealing a session and gaining administrative privileges.
|
|||||
| CVE-2018-13408 | 1 Jirafeau | 1 Jirafeau | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An issue was discovered in Jirafeau before 3.4.1. The "search file by link" form is affected by reflected XSS that could allow, by targeting an administrator, stealing a session and gaining administrative privileges.
|
|||||