Vulnerability index

Browse CVEs

108 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Debian Linux MEDIUM 6.1
CVE-2025-63498

alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter.

Patch available
Fix from $1,600 2025-11-24
Debian Linux MEDIUM 6.3
CVE-2024-44309 KEVEPSS 23%

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.…

Fix: 2.1.1 / 15.1.1+
Fix from $1,600 2024-11-20
Debian Linux MEDIUM 6.1
CVE-2024-37383 KEVEPSS 73%

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

Fix: 1.5.7 / 1.6.7+
Fix from $1,600 2024-06-07
Debian Linux MEDIUM 6.1
CVE-2024-37384

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.

Fix: 1.5.7 / 1.6.7+
Fix from $1,600 2024-06-07
Debian Linux MEDIUM 6.1
CVE-2023-46734

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and pr…

Fix: 4.4.51 / 5.4.31+
Fix from $1,600 2023-11-10
Debian Linux MEDIUM 5.4
CVE-2023-5631 KEVEPSS 76%

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because …

Fix: 1.4.15 / 1.5.5+
Fix from $1,600 2023-10-18
Debian Linux HIGH 7.3
CVE-2023-3550

Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attack…

No fix yet
Fix from $1,950 2023-09-25
Debian Linux MEDIUM 6.1
CVE-2023-43770 KEVEPSS 58%

Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/l…

Fix: 1.4.14 / 1.5.4+
Fix from $1,600 2023-09-22
Debian Linux MEDIUM 6.1
CVE-2022-46391

AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.

Fix: after 7.8
Fix from $1,600 2022-12-04
Debian Linux MEDIUM 5.4
CVE-2022-39348

Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not match a configured host `twi…

Fix: 22.10.0+
Fix from $1,600 2022-10-26
Debian Linux MEDIUM 5.4
CVE-2018-25047

In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that coul…

Fix: 3.1.47 / 4.2.1+
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 5.4
CVE-2022-26874

lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware…

Fix: 2.2.4+
Fix from $1,600 2022-03-11
Debian Linux MEDIUM 5.4
CVE-2021-23225

Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during cr…

Mitigation only
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 6.1
CVE-2021-46144

Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets (CSS) token sequences.

Fix: 1.4.13 / 1.5.2+
Fix from $1,600 2022-01-06
Debian Linux MEDIUM 6.1
CVE-2021-45085

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user vis…

Fix: 40.4 / 41.1+
Fix from $1,600 2021-12-16
Debian Linux MEDIUM 6.1
CVE-2021-45086

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF…

Fix: 40.4 / 41.1+
Fix from $1,600 2021-12-16
Debian Linux MEDIUM 6.1
CVE-2021-45087

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page …

Fix: 40.4 / 41.1+
Fix from $1,600 2021-12-16
Debian Linux MEDIUM 6.1
CVE-2021-45088

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.

Fix: 40.4 / 41.1+
Fix from $1,600 2021-12-16
Debian Linux MEDIUM 6.1
CVE-2021-43331

In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS.

Fix: 2.1.36+
Fix from $1,600 2021-11-12
Debian Linux MEDIUM 6.1
CVE-2020-23226

Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) gr…

No fix yet
Fix from $1,600 2021-08-27
Debian Linux CRITICAL 9.6
CVE-2021-3693

LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, thi…

Fix: after 1.8.17
Fix from $2,300 2021-08-23
Debian Linux CRITICAL 9.6
CVE-2021-3694

LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this fla…

Fix: after 1.8.17
Fix from $2,300 2021-08-23
Debian Linux MEDIUM 5.4
CVE-2021-37695

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](…

Fix: 4.16.2 / 21.1.4+
Fix from $1,600 2021-08-13
Debian Linux MEDIUM 6.1
CVE-2020-36306

Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.

Fix: 4.0.7 / 4.1.1+
Fix from $1,600 2021-04-06
Debian Linux MEDIUM 6.1
CVE-2020-36307

Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.

Fix: 4.0.7 / 4.1.1+
Fix from $1,600 2021-04-06
Debian Linux MEDIUM 6.1
CVE-2021-30154

An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* me…

Fix: 1.31.12 / 1.35.2+
Fix from $1,600 2021-04-06
Debian Linux MEDIUM 6.1
CVE-2021-30157

An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChang…

Fix: 1.31.12 / 1.35.2+
Fix from $1,600 2021-04-06
Debian Linux MEDIUM 6.1
CVE-2021-30151

Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.

Fix: after 6.2.0
Fix from $1,600 2021-04-06
Debian Linux MEDIUM 6.1
CVE-2021-28957

An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_only and forms arguments, the …

Fix: 4.6.3+
Fix from $1,600 2021-03-21
Debian Linux MEDIUM 6.1
CVE-2021-26929

An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacke…

Fix: after 5.2.22
Fix from $1,600 2021-02-14