Filtered by CWE-79
Total 41175 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-20349 1 Wtcms Project 1 Wtcms 2024-11-21 5.4 Medium
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.
CVE-2020-20348 1 Wtcms Project 1 Wtcms 2024-11-21 5.4 Medium
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module.
CVE-2020-20347 1 Wtcms Project 1 Wtcms 2024-11-21 5.4 Medium
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module.
CVE-2020-20345 1 Wtcms Project 1 Wtcms 2024-11-21 5.4 Medium
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box.
CVE-2020-20344 1 Wtcms Project 1 Wtcms 2024-11-21 5.4 Medium
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background articles module.
CVE-2020-20285 1 Zzcms 1 Zzcms 2024-11-21 5.4 Medium
There is a XSS in the user login page in zzcms 2019. Users can inject js code by the referer header via user/login.php
CVE-2020-20142 1 Flexmonster 1 Pivot Table \& Charts 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table & Charts 2.7.17.
CVE-2020-20141 1 Flexmonster 1 Pivot Table \& Charts 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.
CVE-2020-20140 1 Flexmonster 1 Pivot Table \& Charts 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Charts 2.7.17.
CVE-2020-20139 1 Flexmonster 1 Pivot Table \& Charts 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table & Charts 2.7.17.
CVE-2020-20138 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4.
CVE-2020-20131 1 Laracms Project 1 Laracms 2024-11-21 5.4 Medium
LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows atackers to execute arbitrary web scripts or HTML via a crafted payload in the page management module.
CVE-2020-20129 1 Laracms Project 1 Laracms 2024-11-21 5.4 Medium
LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content editor.
CVE-2020-20125 1 Earclink 1 Espcms-p8 2024-11-21 6.1 Medium
EARCLINK ESPCMS-P8 contains a cross-site scripting (XSS) vulnerability in espcms_web\espcms_load.php.
CVE-2020-1949 1 Apache 1 Sling Cms 2024-11-21 6.1 Medium
Scripts in Sling CMS before 0.16.0 do not property escape the Sling Selector from URLs when generating navigational elements for the administrative consoles and are vulnerable to reflected XSS attacks.
CVE-2020-1943 1 Apache 1 Ofbiz 2024-11-21 6.1 Medium
Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.
CVE-2020-1941 2 Apache, Oracle 7 Activemq, Communications Diameter Signaling Router, Communications Element Manager and 4 more 2024-11-21 6.1 Medium
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
CVE-2020-1933 2 Apache, Mozilla 2 Nifi, Firefox 2024-11-21 6.1 Medium
A XSS vulnerability was found in Apache NiFi 1.0.0 to 1.10.0. Malicious scripts could be injected to the UI through action by an unaware authenticated user in Firefox. Did not appear to occur in other browsers.
CVE-2020-1771 1 Otrs 1 Otrs 2024-11-21 4.6 Medium
Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript code is executed due to the missing parameter encoding. This issue affects: ((OTRS)) Community Edition: 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
CVE-2020-1766 2 Debian, Otrs 2 Debian Linux, Otrs 2024-11-21 2 Low
Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious javascript from a special crafted SVG file rendered as inline jpg file. This issue affects: ((OTRS)) Community Edition 5.0.x version 5.0.39 and prior versions; 6.0.x version 6.0.24 and prior versions. OTRS 7.0.x version 7.0.13 and prior versions.