Vulnerabilities (CVE)

Filtered by CWE-79
Total 41666 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-18886 1 Helpy.io 1 Helpy 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Helpy v2.1.0 has Stored XSS via the Ticket title.
CVE-2018-18882 1 Controlbyweb 2 X-320m-i, X-320m-i Firmware 2024-11-21 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting (XSS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can inject arbitrary script via setup.html in the web interface.
CVE-2018-18880 1 Columbiaweather 2 Weather Microserver, Weather Microserver Firmware 2024-11-21 3.5 LOW 5.4 MEDIUM
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script.
CVE-2018-18875 1 Columbiaweather 2 Weather Microserver, Weather Microserver Firmware 2024-11-21 3.5 LOW 5.4 MEDIUM
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a stored Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script via changestationname.php.
CVE-2018-18872 1 Kieranoshea 1 Calendar 2024-11-21 3.5 LOW 5.4 MEDIUM
The Kieran O'Shea Calendar plugin before 1.3.11 for WordPress has Stored XSS via the event_title parameter in a wp-admin/admin.php?page=calendar add action, or the category name during category creation at the wp-admin/admin.php?page=calendar-categories URI.
CVE-2018-18868 1 No-cms Project 1 No-cms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
No-CMS 1.1.3 is prone to Persistent XSS via a contact_us name parameter, as demonstrated by the VG48Z5PqVWname parameter.
CVE-2018-18864 1 Loadbalancer 1 Enterprise Va Max 2024-11-21 9.3 HIGH 9.6 CRITICAL
Loadbalancer.org Enterprise VA MAX before 8.3.3 has XSS because Apache HTTP Server logs are displayed.
CVE-2018-18845 1 Advanced Comment System Project 1 Advanced Comment System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
internal/advanced_comment_system/index.php and internal/advanced_comment_system/admin.php in Advanced Comment System, version 1.0, contain a reflected cross-site scripting vulnerability via ACS_path. A remote unauthenticated attacker could potentially exploit this vulnerability to supply malicious HTML or JavaScript code to a vulnerable web application, which is then reflected back to the victim and executed by the web browser. The product is discontinued.
CVE-2018-18841 1 Sem-cms 1 Semcms 2024-11-21 3.5 LOW 4.8 MEDIUM
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexkey parameter.
CVE-2018-18840 1 Sem-cms 1 Semcms 2024-11-21 3.5 LOW 5.4 MEDIUM
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter.
CVE-2018-18825 1 Pagoda Linux Project 1 Pagoda Linux 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Pagoda Linux panel V6.0 has XSS via the verification code associated with an invalid account login. A crafted code is mishandled during rendering of the login log.
CVE-2018-18824 1 Wolfcms 1 Wolf Cms 2024-11-21 3.5 LOW 4.8 MEDIUM
WolfCMS v0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.
CVE-2018-18823 1 Wolfcms 1 Wolf Cms 2024-11-21 3.5 LOW 4.8 MEDIUM
WolfCMS 0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/.
CVE-2018-18816 1 Tibco 3 Jasperreports Server, Jaspersoft, Jaspersoft Reporting And Analytics 2024-11-21 3.5 LOW 8.0 HIGH
The repository component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft Reporting and Analytics for AWS contains a persistent cross site scripting vulnerability. Affected releases are TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.3.4; 6.4.0; 6.4.1; 6.4.2; 6.4.3; 7.1.0, TIBCO JasperReports Server Community Edition: versions up to and including 7.1.0, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.3, TIBCO Jaspersoft for AWS with Multi- Tenancy versions up to and including 7.1.0, and TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 7.1.0.
CVE-2018-18813 1 Tibco 2 Spotfire Analytics Platform For Aws, Spotfire Server 2024-11-21 4.3 MEDIUM 8.8 HIGH
The Spotfire web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains multiple vulnerabilities that may allow persistent and reflected cross-site scripting attacks. Affected releases are TIBCO Software Inc. TIBCO Spotfire Analytics Platform for AWS Marketplace: versions up to and including 10.0.0, and TIBCO Spotfire Server: versions up to and including 7.10.1; 7.11.0; 7.11.1; 7.12.0; 7.13.0; 7.14.0; 10.0.0.
CVE-2018-18807 1 Tibco 1 Statistica Server 2024-11-21 3.5 LOW 7.6 HIGH
The web application of the TIBCO Statistica component of TIBCO Software Inc.'s TIBCO Statistica Server contains vulnerabilities which may allow an authenticated user to perform cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Statistica Server versions up to and including 13.4.0.
CVE-2018-18783 1 Sem-cms 1 Semcms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
XSS was discovered in SEMCMS V3.4 via the semcms_remail.php?type=ok umail parameter.
CVE-2018-18782 1 Dedecms 1 Dedecms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.
CVE-2018-18781 1 Dedecms 1 Dedecms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
DedeCMS 5.7 SP2 allows XSS via the /member/uploads_select.php f or keyword parameter.
CVE-2018-18776 1 Microstrategy 1 Microstrategy Web 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the admin/admin.asp ShowAll parameter. NOTE: this is a deprecated product.