Vulnerability index

Browse CVEs

108 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Debian Linux HIGH 7.5
CVE-2020-35475

In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits…

Fix: 1.35.1+
Fix from $1,950 2020-12-18
Debian Linux MEDIUM 6.1
CVE-2020-35479

MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, t…

Fix: 1.35.1+
Fix from $1,600 2020-12-18
Debian Linux MEDIUM 6.1
CVE-2020-25706

A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template im…

Patch available
Fix from $1,600 2020-11-12
Debian Linux MEDIUM 6.1
CVE-2020-26870

Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree…

Fix: 2.0.17 / 21.1.0.00.01+
Fix from $1,600 2020-10-07
Debian Linux MEDIUM 6.1
CVE-2020-15562

An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail mess…

Fix: 1.2.11 / 1.3.14+
Fix from $1,600 2020-07-06
Debian Linux MEDIUM 5.4
CVE-2020-4051

In Dijit before versions 1.11.11, and greater than or equal to 1.12.0 and less than 1.12.9, and greater than or equal to 1.13.0 and less than 1.13.8,…

Fix: 1.11.11 / 1.12.9+
Fix from $1,600 2020-06-15
Debian Linux MEDIUM 6.1
CVE-2020-13965 KEVEPSS 77%

An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is am…

Fix: 1.3.12 / 1.4.5+
Fix from $1,600 2020-06-09
Debian Linux MEDIUM 6.1
CVE-2020-11082

In Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links. This has b…

Fix: 1.2.1+
Fix from $1,600 2020-05-28
Debian Linux MEDIUM 6.1
CVE-2020-8020

A Improper Neutralization of Input During Web Page Generation vulnerability in open-build-service allows remote attackers to store arbitrary JS code …

Fix: 2020-05-13+
Fix from $1,600 2020-05-13
Debian Linux MEDIUM 6.1
CVE-2020-12625

An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScrip…

Fix: 1.4.4+
Fix from $1,600 2020-05-04
Debian Linux MEDIUM 6.1
CVE-2020-11029

In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scriptin…

Fix: 3.7.33 / 3.8.33+
Fix from $1,600 2020-04-30
Debian Linux MEDIUM 6.1
CVE-2020-12137

GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks a…

Fix: 2.1.30+
Fix from $1,600 2020-04-24
Debian Linux MEDIUM 5.4
CVE-2020-10803

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XS…

Fix: 4.9.5 / 5.0.2+
Fix from $1,600 2020-03-22
Debian Linux MEDIUM 6.1
CVE-2019-10785

dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1.11.9. This is due to dojox.xm…

Fix: 1.11.9 / 1.12.7+
Fix from $1,600 2020-02-13
Debian Linux MEDIUM 6.1
CVE-2020-7106

Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and us…

Fix: 1.2.9+
Fix from $1,600 2020-01-16
Debian Linux MEDIUM 6.1
CVE-2020-1766

Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious java…

Fix: after 7.0.13
Fix from $1,600 2020-01-10
Debian Linux MEDIUM 6.1
CVE-2012-2237

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary we…

Fix: 1.4.3 / 1.5.2+
Fix from $1,600 2019-12-17
Debian Linux MEDIUM 6.1
CVE-2014-4913

ZF2014-03 has a potential cross site scripting vector in multiple view helpers

Fix: 2.2.7 / 2.3.1+
Fix from $1,600 2019-12-15
Debian Linux CRITICAL 9.3
CVE-2019-18345

A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied…

Fix: after 1.1.8
Fix from $2,300 2019-12-12
Debian Linux MEDIUM 6.1
CVE-2013-7371

node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370)

Fix: 2.8.2+
Fix from $1,600 2019-12-11
Debian Linux MEDIUM 6.1
CVE-2013-4158

smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)

Fix: 2.6.9+
Fix from $1,600 2019-12-11
Debian Linux MEDIUM 6.1
CVE-2012-1114

A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_…

Mitigation only
Fix from $1,600 2019-12-05
Debian Linux MEDIUM 6.1
CVE-2012-1115

A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.

Mitigation only
Fix from $1,600 2019-12-05
Debian Linux MEDIUM 6.1
CVE-2012-0812

PostfixAdmin 2.3.4 has multiple XSS vulnerabilities

Mitigation only
Fix from $1,600 2019-11-22
Debian Linux MEDIUM 6.1
CVE-2011-0544

phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.

Fix: after 3.0.6
Fix from $1,600 2019-11-14
Debian Linux MEDIUM 6.1
CVE-2012-4384

letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar

Fix: after 3.3.11
Fix from $1,600 2019-11-13
Debian Linux MEDIUM 6.1
CVE-2009-5046

JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.

Fix: 6.1.22+
Fix from $1,600 2019-11-06
Debian Linux MEDIUM 6.1
CVE-2009-5049

WebApp JSP Snoop page XSS in jetty though 6.1.21.

Fix: after 6.1.21
Fix from $1,600 2019-11-06
Debian Linux HIGH 8.8
CVE-2013-6364

Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book

No fix yet
Fix from $1,950 2019-11-05
Debian Linux MEDIUM 6.1
CVE-2013-4168

Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.

Patch available
Fix from $1,600 2019-11-01