Vulnerabilities (CVE)

Filtered by CWE-79
Total 36793 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-18868 1 No-cms Project 1 No-cms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
No-CMS 1.1.3 is prone to Persistent XSS via a contact_us name parameter, as demonstrated by the VG48Z5PqVWname parameter.
CVE-2018-18864 1 Loadbalancer 1 Enterprise Va Max 2024-11-21 9.3 HIGH 9.6 CRITICAL
Loadbalancer.org Enterprise VA MAX before 8.3.3 has XSS because Apache HTTP Server logs are displayed.
CVE-2018-18845 1 Advanced Comment System Project 1 Advanced Comment System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
internal/advanced_comment_system/index.php and internal/advanced_comment_system/admin.php in Advanced Comment System, version 1.0, contain a reflected cross-site scripting vulnerability via ACS_path. A remote unauthenticated attacker could potentially exploit this vulnerability to supply malicious HTML or JavaScript code to a vulnerable web application, which is then reflected back to the victim and executed by the web browser. The product is discontinued.
CVE-2018-18841 1 Sem-cms 1 Semcms 2024-11-21 3.5 LOW 4.8 MEDIUM
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexkey parameter.
CVE-2018-18840 1 Sem-cms 1 Semcms 2024-11-21 3.5 LOW 5.4 MEDIUM
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter.
CVE-2018-18825 1 Pagoda Linux Project 1 Pagoda Linux 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Pagoda Linux panel V6.0 has XSS via the verification code associated with an invalid account login. A crafted code is mishandled during rendering of the login log.
CVE-2018-18824 1 Wolfcms 1 Wolf Cms 2024-11-21 3.5 LOW 4.8 MEDIUM
WolfCMS v0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.
CVE-2018-18823 1 Wolfcms 1 Wolf Cms 2024-11-21 3.5 LOW 4.8 MEDIUM
WolfCMS 0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.
CVE-2018-18816 1 Tibco 3 Jasperreports Server, Jaspersoft, Jaspersoft Reporting And Analytics 2024-11-21 3.5 LOW 8.0 HIGH
The repository component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and Analytics for AWS contains a persistent cross site scripting vulnerability. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi- Tenancy versions up to and including 7.1.0, and TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.
CVE-2018-18813 1 Tibco 2 Spotfire Analytics Platform For Aws, Spotfire Server 2024-11-21 4.3 MEDIUM 8.8 HIGH
The Spotfire web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains multiple vulnerabilities that may allow persistent and reflected cross-site scripting attacks. Affected releases are TIBCO Software Inc. TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 10.0.0, and TIBCO Spotfire Server: versions up to and including 7.10.1; 7.11.0; 7.11.1; 7.12.0; 7.13.0; 7.14.0; 10.0.0.
CVE-2018-18807 1 Tibco 1 Statistica Server 2024-11-21 3.5 LOW 7.6 HIGH
The web application of the TIBCO Statistica component of TIBCO Software Inc.'s TIBCO Statistica Server contains vulnerabilities which may allow an authenticated user to perform cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Statistica Server versions up to and including 13.4.0.
CVE-2018-18783 1 Sem-cms 1 Semcms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
XSS was discovered in SEMCMS V3.4 via the semcms_remail.php?type=ok umail parameter.
CVE-2018-18782 1 Dedecms 1 Dedecms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.
CVE-2018-18781 1 Dedecms 1 Dedecms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
DedeCMS 5.7 SP2 allows XSS via the /member/uploads_select.php f or keyword parameter.
CVE-2018-18776 1 Microstrategy 1 Microstrategy Web 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the admin/admin.asp ShowAll parameter. NOTE: this is a deprecated product.
CVE-2018-18775 1 Microstrategy 1 Microstrategy Web 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Login.asp Msg parameter. NOTE: this is a deprecated product.
CVE-2018-18774 1 Control-webpanel 1 Webpanel 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
CVE-2018-18745 1 Sem-cms 1 Semcms 2024-11-21 3.5 LOW 4.8 MEDIUM
An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Menu.php?lgid=1 during editing.
CVE-2018-18744 1 Sem-cms 1 Semcms 2024-11-21 3.5 LOW 4.8 MEDIUM
An XSS issue was discovered in SEMCMS 3.4 via the fifth text box to the admin/SEMCMS_Main.php URI.
CVE-2018-18743 1 Sem-cms 1 Semcms 2024-11-21 3.5 LOW 4.8 MEDIUM
An XSS issue was discovered in SEMCMS 3.4 via the second text field to the admin/SEMCMS_Categories.php?pid=1&lgid=1 URI.