Filtered by CWE-79
Total 39862 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2017-1000506 1 Mautic 1 Mautic 2024-11-21 N/A
Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code.
CVE-2017-1000495 1 Quickappscms 1 Quickapps Cms 2024-11-21 N/A
QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account
CVE-2017-1000492 1 Leanote 1 Desktop 2024-11-21 N/A
Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration
CVE-2017-1000491 1 Shiba Project 1 Shiba 2024-11-21 N/A
Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration.
CVE-2017-1000488 2 Acquia, Mautic 2 Mautic, Mautic 2024-11-21 N/A
Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form.
CVE-2017-1000482 1 Plone 1 Plone 2024-11-21 N/A
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.
CVE-2017-1000478 1 Elabftw 1 Elabftw 2024-11-21 N/A
ELabftw version 1.7.8 is vulnerable to stored cross-site scripting in the experiment infos component resulting in arbitrary execution of JavaScript and denial of service.
CVE-2017-1000467 1 Lavalite 1 Lavalite 2024-11-21 N/A
LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which can result in disruption of service and execution of javascript code.
CVE-2017-1000466 1 Invoiceninja 1 Invoice Ninja 2024-11-21 N/A
Invoice Ninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page, which can result in disruption of service and execution of javascript code.
CVE-2017-1000465 1 Sulu 1 Sulu-standard 2024-11-21 N/A
Sulu-standard version 1.6.6 is vulnerable to stored cross-site scripting vulnerability, within the page creation page, which can result in disruption of service and execution of javascript code.
CVE-2017-1000463 1 Leafpub 1 Leafpub 2024-11-21 N/A
Leafpub version 1.2.0-beta6 is vulnerable to stored cross-site scripting vulnerability, within the edit blog post page, which can result in disruption of service and execution of javascript code.
CVE-2017-1000462 1 Bookstackapp 1 Bookstack 2024-11-21 N/A
BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code.
CVE-2017-1000459 1 Leanote 1 Leanote 2024-11-21 N/A
Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes
CVE-2017-1000457 1 Mojoportal 1 Mojoportal 2024-11-21 N/A
Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected cross-site scripting for user accounts assigned either the "Administrators" or "Content Administrators" role.
CVE-2017-1000443 1 Openhacker Project 1 Openhacker 2024-11-21 N/A
Eleix Openhacker version 0.1.47 is vulnerable to a XSS vulnerability in the bank transactions component resulting in arbitrary code execution in the browser.
CVE-2017-1000442 1 Passbolt 1 Passbolt Api 2024-11-21 N/A
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
CVE-2017-1000431 1 Ez 1 Ez Publish 2024-11-21 N/A
eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.
CVE-2017-1000429 1 Finecms Project 1 Finecms 2024-11-21 N/A
rui Li finecms 5.0.10 is vulnerable to a reflected XSS in the file Weixin.php.
CVE-2017-1000428 1 Flatcore 1 Flatcore-cms 2024-11-21 N/A
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-Agent string.
CVE-2017-1000427 1 Marked Project 1 Marked 2024-11-21 N/A
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.