Vulnerability index

Browse CVEs

166 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Syncope MEDIUM 5.4
CVE-2019-17557

It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage parameters. By this mean, a user acce…

Fix: 2.0.15 / 2.1.6+
Fix from $1,600 2020-05-04
Ofbiz MEDIUM 6.1
CVE-2020-1943EPSS 97%

Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.

Fix: after 16.11.07
Fix from $1,600 2020-04-01
Sling Cms MEDIUM 6.1
CVE-2020-1949

Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative c…

Fix: 0.16.0+
Fix from $1,600 2020-04-01
Struts MEDIUM 6.1
CVE-2015-2992EPSS 6%

Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.

Fix: 2.3.20+
Fix from $1,600 2020-02-27
Nifi MEDIUM 6.1
CVE-2020-1933

A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticate…

Fix: after 1.10.0
Fix from $1,600 2020-01-28
Cxf MEDIUM 6.1
CVE-2019-17573EPSS 7%

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a r…

Fix: 3.3.5+
Fix from $1,600 2020-01-16
Atlas MEDIUM 6.1
CVE-2019-10070

Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality

Mitigation only
Fix from $1,600 2019-11-18
HTTP Server MEDIUM 6.1
CVE-2019-10092EPSS 81%

In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the…

Fix: after 9.5
Fix from $1,600 2019-09-26
Jspwiki MEDIUM 6.1
CVE-2019-10090

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related …

Fix: after 2.10.5
Fix from $1,600 2019-09-23
Jspwiki MEDIUM 6.1
CVE-2019-12407

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related …

Fix: after 2.10.5
Fix from $1,600 2019-09-23
Jspwiki MEDIUM 6.1
CVE-2019-10087

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related …

Fix: after 2.10.5
Fix from $1,600 2019-09-23
Jspwiki MEDIUM 6.1
CVE-2019-10089

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related …

Fix: after 2.10.5
Fix from $1,600 2019-09-23
Jspwiki MEDIUM 6.1
CVE-2019-12404

On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related …

Fix: after 2.10.5
Fix from $1,600 2019-09-23
Ofbiz MEDIUM 6.1
CVE-2019-10073EPSS 5%

The "Blog", "Forum", "Contact Us" screens of the template "ecommerce" application bundled in Apache OFBiz are weak to Stored XSS attacks. Mitigation:…

Fix: after 16.11.05
Fix from $1,600 2019-09-11
Ranger MEDIUM 6.1
CVE-2019-12397

Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.0.0 or later version of Apach…

Fix: after 1.2.0
Fix from $1,600 2019-08-08
Roller MEDIUM 6.1
CVE-2019-0234

A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user inpu…

Mitigation only
Fix from $1,600 2019-07-15
Allura MEDIUM 6.1
CVE-2019-10085EPSS 5%

In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or editing tickets. The XSS execu…

Fix: 1.11.0+
Fix from $1,600 2019-06-19
Tomcat MEDIUM 6.1
CVE-2019-0221EPSS 46%

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is…

Fix: after 9.0.17
Fix from $1,600 2019-05-28
Jspwiki MEDIUM 6.1
CVE-2019-10076

A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacki…

Fix: after 2.11.0
Fix from $1,600 2019-05-20
Jspwiki MEDIUM 6.1
CVE-2019-10077

A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.

Fix: after 2.11.0
Fix from $1,600 2019-05-20
Jspwiki MEDIUM 6.1
CVE-2019-10078

A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijac…

Fix: after 2.11.0
Fix from $1,600 2019-05-20
Uimaducc MEDIUM 6.1
CVE-2018-8035

This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which ru…

Fix: after 2.2.2
Fix from $1,600 2019-05-01
Archiva MEDIUM 6.5
CVE-2019-0213

In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. the logo URL. The vulnerabili…

Fix: 2.2.4+
Fix from $1,600 2019-04-30
Pluto MEDIUM 6.1
CVE-2019-0186EPSS 21%

The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks. Mitigation: * Uni…

No fix yet
Fix from $1,600 2019-04-26
Zeppelin MEDIUM 6.1
CVE-2018-1328EPSS 6%

Apache Zeppelin prior to 0.8.0 had a stored XSS issue via Note permissions. Issue reported by "Josna Joseph".

Fix: 0.8.0+
Fix from $1,600 2019-04-23
Pony Mail MEDIUM 6.1
CVE-2019-0218EPSS 5%

A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail interface.

Fix: after 0.10
Fix from $1,600 2019-04-22
Jspwiki MEDIUM 6.1
CVE-2019-0224EPSS 5%

In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on th…

Fix: after 2.10.5
Fix from $1,600 2019-03-28
Airflow MEDIUM 5.5
CVE-2018-20244

In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascr…

Fix: 1.10.2+
Fix from $1,600 2019-02-27
Jspwiki MEDIUM 6.1
CVE-2018-20242EPSS 5%

A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking.

Fix: after 2.10.5
Fix from $1,600 2019-02-11
Nifi MEDIUM 6.1
CVE-2018-17193

The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attac…

Fix: after 1.7.1
Fix from $1,600 2018-12-19