Vulnerabilities (CVE)

Filtered by CWE-79
Total 36805 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-5362 1 Wpglobus 1 Wpglobus 2024-11-21 3.5 LOW 4.8 MEDIUM
The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][page] parameter to wp-admin/options.php.
CVE-2018-5331 1 Discuz 1 Discuzx 2024-11-21 3.5 LOW 5.4 MEDIUM
Discuz! DiscuzX X3.4 has XSS via the view parameter to include/space/space_poll.php, as demonstrated by a mod=space do=poll request to home.php.
CVE-2018-5316 1 Patsatech 1 Sagepay Server Gateway For Woocommerce 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for WordPress has XSS via the includes/pages/redirect.php page parameter.
CVE-2018-5312 1 Wpshopmart 1 Tabs Responsive 2024-11-21 3.5 LOW 5.4 MEDIUM
The tabs-responsive plugin 1.8.0 for WordPress has XSS via the post_title parameter to wp-admin/post.php.
CVE-2018-5311 1 Tonjoostudio 1 Easy Custom Auto Excerpt 2024-11-21 3.5 LOW 5.4 MEDIUM
The Easy Custom Auto Excerpt plugin 2.4.6 for WordPress has XSS via the tonjoo_ecae_options[custom_css] parameter to the wp-admin/admin.php?page=tonjoo_excerpt URI.
CVE-2018-5307 1 Sonatype 1 Nexus Repository Manager 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 2.x before 2.14.6 allow remote attackers to inject arbitrary web script or HTML via (1) the repoId or (2) format parameter to service/siesta/healthcheck/healthCheckFileDetail/.../index.html; (3) the filename in the "File Upload" functionality of the Staging Upload; (4) the username when creating a new user; or (5) the IQ Server URL field in the IQ Server Connection functionality.
CVE-2018-5306 1 Sonatype 1 Nexus Repository Manager 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 3.x before 3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the repoId or (2) format parameter to service/siesta/healthcheck/healthCheckFileDetail/.../index.html; (3) the filename in the "File Upload" functionality of the Staging Upload; (4) the username when creating a new user; or (5) the IQ Server URL field in the IQ Server Connection functionality.
CVE-2018-5303 1 Impinj 2 R420 Rfid Reader, R420 Rfid Reader Firmware 2024-11-21 3.5 LOW 5.4 MEDIUM
An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The license key parameter of the web application is vulnerable to Cross Site Scripting; this vulnerability allows an attacker to send malicious code to another user.
CVE-2018-5293 1 Gd Rating System Project 1 Gd Rating System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.
CVE-2018-5292 1 Gd Rating System Project 1 Gd Rating System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
CVE-2018-5288 1 Gd Rating System Project 1 Gd Rating System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
CVE-2018-5286 1 Gd Rating System Project 1 Gd Rating System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-about page.
CVE-2018-5284 1 Wpscoop 1 Imageinject 2024-11-21 3.5 LOW 4.8 MEDIUM
The ImageInject plugin 1.15 for WordPress has XSS via the flickr_appid parameter to wp-admin/options-general.php.
CVE-2018-5281 1 Sonicwall 8 Nsa 250m, Nsa 2600, Nsa 2650 and 5 more 2024-11-21 3.5 LOW 5.4 MEDIUM
SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens.
CVE-2018-5280 1 Sonicwall 8 Nsa 250m, Nsa 2600, Nsa 2650 and 5 more 2024-11-21 3.5 LOW 5.4 MEDIUM
SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.
CVE-2018-5263 1 Stackideas 1 Easydiscuss 2024-11-21 3.5 LOW 5.4 MEDIUM
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.
CVE-2018-5249 1 Shaarli Project 1 Shaarli 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php).
CVE-2018-5233 1 Getgrav 1 Grav Cms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/tools.
CVE-2018-5232 1 Atlassian 2 Jira, Jira Server 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.10.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuetype parameter.
CVE-2018-5230 1 Atlassian 2 Jira, Jira Server 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the error message of custom fields when an invalid value is specified.