Vulnerabilities (CVE)

Filtered by CWE-79
Total 37120 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-9410 2 Oracle, Tibco 3 Retail Order Broker, Jasperreports Library, Jasperreports Server 2024-11-21 6.8 MEDIUM 7.3 HIGH
The report generator component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an attacker to exploit HTML injection to gain full control of a web interface containing the output of the report generator component with the privileges of any user that views the affected report(s). The attacker can theoretically exploit this vulnerability when other users view a maliciously generated report, where those reports use Fusion Charts and a data source with contents controlled by the attacker. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Library: versions 7.1.1 and below, versions 7.2.0 and 7.2.1, version 7.3.0, version 7.5.0, TIBCO JasperReports Library for ActiveMatrix BPM: versions 7.1.1 and below, TIBCO JasperReports Server: versions 7.1.1 and below, version 7.2.0, version 7.5.0, TIBCO JasperReports Server for AWS Marketplace: versions 7.5.0 and below, and TIBCO JasperReports Server for ActiveMatrix BPM: versions 7.1.1 and below.
CVE-2020-9405 1 Iblsoft 1 Online Weather 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page.
CVE-2020-9393 1 Supsystic 1 Pricing Table By Supsystic 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS.
CVE-2020-9390 1 Squaredup 1 Squaredup 2024-11-21 3.5 LOW 5.4 MEDIUM
SquaredUp allowed Stored XSS before version 4.6.0. A user was able to create a dashboard that executed malicious content in iframe or by uploading an SVG that contained a script.
CVE-2020-9371 1 Codepeople 1 Appointment Booking Calendar 2024-11-21 3.5 LOW 4.8 MEDIUM
Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to inject arbitrary JavaScript or HTML.
CVE-2020-9350 1 Sas 1 Visual Analytics 2024-11-21 3.5 LOW 5.4 MEDIUM
Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly.
CVE-2020-9344 1 Atlassian 1 Subversion Application Lifecycle Management 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Subversion ALM for the enterprise before 8.8.2 allows reflected XSS at multiple locations.
CVE-2020-9339 1 Soplanning 1 Soplanning 2024-11-21 3.5 LOW 5.4 MEDIUM
SOPlanning 1.45 allows XSS via the Name or Comment to status.php.
CVE-2020-9338 1 Soplanning 1 Soplanning 2024-11-21 3.5 LOW 5.4 MEDIUM
SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field.
CVE-2020-9336 1 Fauzantrif Election Project 1 Fauzantrif Election 2024-11-21 3.5 LOW 5.4 MEDIUM
fauzantrif eLection 2.0 has XSS via the Admin Dashboard -> Settings -> Election -> "message if election is closed" field.
CVE-2020-9335 1 10web 1 Photo Gallery 2024-11-21 3.5 LOW 4.8 MEDIUM
Multiple stored XSS vulnerabilities exist in the 10Web Photo Gallery plugin before 1.5.46 WordPress. Successful exploitation of this vulnerability would allow a authenticated admin user to inject arbitrary JavaScript code that is viewed by other users.
CVE-2020-9334 1 Enviragallery 1 Envira Gallery 2024-11-21 3.5 LOW 5.4 MEDIUM
A stored XSS vulnerability exists in the Envira Photo Gallery plugin through 1.7.6 for WordPress. Successful exploitation of this vulnerability would allow a authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.
CVE-2020-9314 1 Oracle 1 Iplanet Web Server 2024-11-21 4.9 MEDIUM 4.8 MEDIUM
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516. NOTE: a related support policy can be found in the www.oracle.com references attached to this CVE.
CVE-2020-9311 1 Silverstripe 1 Silverstripe 2024-11-21 3.5 LOW 5.4 MEDIUM
In SilverStripe through 4.5, malicious users with a valid Silverstripe CMS login (usually CMS access) can craft profile information which can lead to XSS for other users through specially crafted login form URLs.
CVE-2020-9299 1 Netflix 1 Dispatch 2024-11-21 3.5 LOW 5.4 MEDIUM
There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, Incident Type, Tag Type, and Incident Filter. This vulnerability can be exploited by an authenticated user.
CVE-2020-9288 1 Fortinet 1 Fortiwlc 2024-11-21 3.5 LOW 5.4 MEDIUM
An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the ESS profile or the Radius Profile.
CVE-2020-9281 4 Ckeditor, Drupal, Fedoraproject and 1 more 11 Ckeditor, Drupal, Fedora and 8 more 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
CVE-2020-9092 1 Huawei 2 Mate 20, Mate 20 Firmware 2024-11-21 2.1 LOW 4.6 MEDIUM
HUAWEI Mate 20 versions earlier than 10.1.0.163(C00E160R3P8) have a JavaScript injection vulnerability. A module does not verify a specific input. This could allow attackers to bypass filter mechanism to launch JavaScript injection. This could compromise normal service of the affected module.
CVE-2020-9056 1 Periscopeholdings 1 Buyspeed 2024-11-21 3.5 LOW 3.9 LOW
Periscope BuySpeed version 14.5 is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to store arbitrary JavaScript within the application. This JavaScript is subsequently displayed by the application without sanitization and is executed in the browser of the user, which could possibly cause website redirection, session hijacking, or information disclosure. This vulnerability has been patched in BuySpeed version 15.3.
CVE-2020-9055 1 Versiant 1 Lynx Customer Service Portal 2024-11-21 3.5 LOW 3.9 LOW
Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malicious JavaScript that is stored and displayed to the end user. This could lead to website redirects, session cookie hijacking, or information disclosure.