Total
36676 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-1000465 | 1 Sulu | 1 Sulu-standard | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Sulu-standard version 1.6.6 is vulnerable to stored cross-site scripting vulnerability, within the page creation page, which can result in disruption of service and execution of javascript code. | |||||
CVE-2017-1000463 | 1 Leafpub | 1 Leafpub | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Leafpub version 1.2.0-beta6 is vulnerable to stored cross-site scripting vulnerability, within the edit blog post page, which can result in disruption of service and execution of javascript code. | |||||
CVE-2017-1000462 | 1 Bookstackapp | 1 Bookstack | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code. | |||||
CVE-2017-1000459 | 1 Leanote | 1 Leanote | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes | |||||
CVE-2017-1000457 | 1 Mojoportal | 1 Mojoportal | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected cross-site scripting for user accounts assigned either the "Administrators" or "Content Administrators" role. | |||||
CVE-2017-1000443 | 1 Openhacker Project | 1 Openhacker | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Eleix Openhacker version 0.1.47 is vulnerable to a XSS vulnerability in the bank transactions component resulting in arbitrary code execution in the browser. | |||||
CVE-2017-1000442 | 1 Passbolt | 1 Passbolt Api | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace | |||||
CVE-2017-1000431 | 1 Ez | 1 Ez Publish | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials. | |||||
CVE-2017-1000429 | 1 Finecms Project | 1 Finecms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
rui Li finecms 5.0.10 is vulnerable to a reflected XSS in the file Weixin.php. | |||||
CVE-2017-1000428 | 1 Flatcore | 1 Flatcore-cms | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-Agent string. | |||||
CVE-2017-1000427 | 1 Marked Project | 1 Marked | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser. | |||||
CVE-2017-1000426 | 1 Omniscale | 1 Mapproxy | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure. | |||||
CVE-2017-1000425 | 1 Liferay | 1 Liferay Portal | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter. | |||||
CVE-2017-1000404 | 1 Jenkins | 1 Delivery Pipeline | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted URLs. | |||||
CVE-2017-1000392 | 1 Jenkins | 1 Jenkins | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters. | |||||
CVE-2017-1000389 | 1 Jenkins | 1 Global-build-stats | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained request parameters. These responses had the Content Type: text/html, so could have been interpreted as HTML by clients, resulting in a potential reflected cross-site scripting vulnerability. Additionally, some URLs provided by global-build-stats plugin that modify data did not require POST requests to be sent, resulting in a potential cross-site request forgery vulnerability. | |||||
CVE-2017-1000386 | 1 Jenkins | 1 Active Choices | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Active Choices plugin version 1.5.3 and earlier allowed users with Job/Configure permission to provide arbitrary HTML to be shown on the 'Build With Parameters' page through the 'Active Choices Reactive Reference Parameter' type. This could include, for example, arbitrary JavaScript. Active Choices now sanitizes the HTML inserted on the 'Build With Parameters' page if and only if the script is executed in a sandbox. As unsandboxed scripts are subject to administrator approval, it is up to the administrator to allow or disallow problematic script output. | |||||
CVE-2017-0931 | 1 Html-janitor Project | 1 Html-janitor | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
html-janitor node module suffers from a Cross-Site Scripting (XSS) vulnerability via clean() accepting user-controlled values. | |||||
CVE-2017-0924 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the labels component resulting in persistent cross site scripting. | |||||
CVE-2017-0923 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site scripting. |