Total
42233 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2018-11709 | 1 Gvectors | 1 Wpforo Forum | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
wpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated Reflected Cross-Site Scripting (XSS) via the URI.
|
|||||
| CVE-2018-11690 | 1 Balbooa | 1 Gridbox | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
|
|||||
| CVE-2018-11689 | 2 Hanwha-security, Samsung | 19 Hrd-1641, Hrd-1641 Firmware, Hrd-1642 and 16 more | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)
|
|||||
| CVE-2018-11688 | 1 Igniterealtime | 1 Openfire | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Ignite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
|
|||||
| CVE-2018-11651 | 1 Graylog | 1 Graylog | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashboardPage.jsx.
|
|||||
| CVE-2018-11650 | 1 Graylog | 1 Graylog | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
|
|||||
| CVE-2018-11649 | 1 Gethue | 1 Hue | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Hue 3.12 has XSS via the /pig/save/ name and script parameters.
|
|||||
| CVE-2018-11647 | 1 Oauth2orize-fprm Project | 1 Oauth2orize-fprm | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
index.js in oauth2orize-fprm before 0.2.1 has XSS via a crafted URL.
|
|||||
| CVE-2018-11628 | 1 Emssoftware | 1 Ems Master Calendar | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malicious attackers to send a crafted URL for XSS.
|
|||||
| CVE-2018-11627 | 2 Redhat, Sinatrarb | 2 Cloudforms, Sinatra | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
|
|||||
| CVE-2018-11588 | 1 Centreon | 2 Centreon, Centreon Web | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or command description, resulting in stored XSS. This is related to www/include/core/menu/menu.php and www/include/configuration/configObject/command/formArguments.php.
|
|||||
| CVE-2018-11583 | 1 Seacms | 1 Seacms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter.
|
|||||
| CVE-2018-11581 | 1 Brother | 4 Hl-l2340d, Hl-l2340d Firmware, Hl-l2380dw and 1 more | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
Cross-site scripting (XSS) vulnerability on Brother HL series printers allows remote attackers to inject arbitrary web script or HTML via the url parameter to etc/loginerror.html.
|
|||||
| CVE-2018-11580 | 1 Multidots | 1 Mass Pages\/posts Creator | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
An issue was discovered in mass-pages-posts-creator.php in the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2 for WordPress. Any logged in user can launch Mass Pages/Posts creation with custom content. There is no nonce or user capability check, so anyone can launch a DoS attack against a site and create hundreds of thousands of posts with custom content.
|
|||||
| CVE-2018-11572 | 1 Clippercms | 1 Clippercms | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.
|
|||||
| CVE-2018-11568 | 1 Cactusthemes | 1 Gameplan-event And Gym Fitness | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Reflected XSS is possible in the GamePlan theme through 1.5.13.2 for WordPress because of insufficient input sanitization, as demonstrated by the s parameter. In some (but not all) cases, the '<' and '>' characters have < and > representations.
|
|||||
| CVE-2018-11564 | 1 Pagekit | 1 Pagekit | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG format. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to "/storage/poc.svg" that will point to http://localhost/pagekit/storage/poc.svg. When a user comes along to click that link, it will trigger a XSS attack.
|
|||||
| CVE-2018-11562 | 1 Misp | 1 Misp | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious link for an event view and then clicks on the deleted attributes quick filter.
|
|||||
| CVE-2018-11559 | 1 Domainmod | 1 Domainmod | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_last_name parameter.
|
|||||
| CVE-2018-11558 | 1 Domainmod | 1 Domainmod | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter.
|
|||||
| CVE-2018-11557 | 1 Yiban | 1 Easy Class Education Platform | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
YIBAN Easy class education platform 2.0 has XSS via the articlelist.php k parameter.
|
|||||
| CVE-2018-11553 | 1 Sgin | 1 Xiangyun Platform | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php.
|
|||||
| CVE-2018-11552 | 1 Nch | 1 Axon Pbx | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. The vulnerability exists due to insufficient filtration of user-supplied data. A remote attacker can execute arbitrary HTML and script code in a browser in the context of the vulnerable application.
|
|||||
| CVE-2018-11532 | 1 Changuondyu Advanced Statistics Project | 1 Changuondyu Advanced Statistics | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field.
|
|||||
| CVE-2018-11522 | 1 Yosoro Project | 1 Yosoro | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Yosoro 1.0.4 has stored XSS.
|
|||||
| CVE-2018-11512 | 1 Creatiwity | 1 Witycms | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to admin/settings/general.
|
|||||
| CVE-2018-11501 | 1 Website Seller Script Project | 1 Website Seller Script | 2024-11-21 | 6.0 MEDIUM | 8.8 HIGH |
|
PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS.
|
|||||
| CVE-2018-11487 | 1 Phpmywind | 1 Phpmywind | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.
|
|||||
| CVE-2018-11486 | 1 Multidots | 1 Advance Search For Woocommerce | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
An issue was discovered in the MULTIDOTS Advance Search for WooCommerce plugin 1.0.9 and earlier for WordPress. This plugin is vulnerable to a stored Cross-site scripting (XSS) vulnerability. A non-authenticated user can save the plugin settings and inject malicious JavaScript code in the Custom CSS textarea field, which will be loaded on every site page.
|
|||||
| CVE-2018-11485 | 1 Multidots | 1 Woocommerce Quick Reports | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.
|
|||||
| CVE-2018-11473 | 1 Monstra | 1 Monstra | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).
|
|||||
| CVE-2018-11472 | 1 Monstra | 1 Monstra | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
Monstra CMS 3.0.4 has Reflected XSS during Login (i.e., the login parameter to admin/index.php).
|
|||||
| CVE-2018-11471 | 1 Getcockpit | 1 Cockpit | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
Cockpit 0.5.5 has XSS via a collection, form, or region.
|
|||||
| CVE-2018-11450 | 1 Siemens | 1 Teamcenter Product Lifecycle Management | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
A reflected Cross-Site-Scripting (XSS) vulnerability has been identified in Siemens PLM Software TEAMCENTER (V9.1.2.5). If a user visits the login portal through the URL crafted by the attacker, the attacker can insert html/javascript and thus alter/rewrite the login portal page. Siemens PLM Software TEAMCENTER V9.1.3 and newer are not affected.
|
|||||
| CVE-2018-11449 | 1 Siemens | 2 Scalance M875, Scalance M875 Firmware | 2024-11-21 | 2.1 LOW | 7.8 HIGH |
|
A vulnerability has been identified in SCALANCE M875 (All versions). An attacker with access to the local file system might obtain passwords for administrative users. Successful exploitation requires read access to files on the local file system. A successful attack could allow an attacker to obtain administrative passwords. At the time of advisory publication no public exploitation of this security vulnerability was known.
|
|||||
| CVE-2018-11448 | 1 Siemens | 2 Scalance M875, Scalance M875 Firmware | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
|
A vulnerability has been identified in SCALANCE M875 (All versions). The web interface on port 443/tcp could allow a stored Cross-Site Scripting (XSS) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires that the attacker has access to the web interface of an affected device. The attacker must be authenticated as administrative user on the web interface. Afterwards, a legitimate user must access the web interface. A successful attack could a ...
Show More |
|||||
| CVE-2018-11443 | 1 Easyservice Billing Project | 1 Easyservice Billing | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
|
|||||
| CVE-2018-11430 | 1 Moderator Log Notes Project | 1 Moderator Log Notes | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
|
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea.
|
|||||
| CVE-2018-11415 | 1 Sap | 1 Internet Transaction Server | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product.
|
|||||
| CVE-2018-11404 | 1 Domainmod | 1 Domainmod | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.
|
|||||