Total
41153 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-18165 | 1 Laobancms | 1 Laobancms | 2024-11-21 | 4.8 Medium |
| Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Website SEO Keywords" field on the page "admin/info.php?shuyu". | ||||
| CVE-2020-18158 | 1 Hucart | 1 Hucart | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in HuCart 5.7.4 via nickname in index.php. | ||||
| CVE-2020-18145 | 1 Baidu | 1 Umeditor | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting (XSS) vulnerability in umeditor v1.2.3 via /public/common/umeditor/php/getcontent.php. | ||||
| CVE-2020-18126 | 1 Indexhibit | 1 Indexhibit | 2024-11-21 | 5.4 Medium |
| Multiple stored cross-site scripting (XSS) vulnerabilities in the Sections module of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML. | ||||
| CVE-2020-18125 | 1 Indexhibit | 1 Indexhibit | 2024-11-21 | 6.1 Medium |
| A reflected cross-site scripting (XSS) vulnerability in the /plugin/ajax.php component of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML. | ||||
| CVE-2020-18102 | 1 Hotels Server Project | 1 Hotels Server | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting (XSS) in Hotels_Server v1.0 allows remote attackers to execute arbitrary code by injecting crafted commands the data fields in the component "/controller/publishHotel.php". | ||||
| CVE-2020-18084 | 1 Yzmcms | 1 Yzmcms | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into the "referer" field of a POST request to the component "/member/index/login.html" when logging in. | ||||
| CVE-2020-18066 | 1 Zrlog | 1 Zrlog | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting vulnerability in ZrLog 2.1.0 via the (1) userName and (2) email parameters in post/addComment. | ||||
| CVE-2020-18065 | 1 Popojicms | 1 Popojicms | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability exists in PopojiCMS 2.0.1 in admin.php?mod=menumanager--------- edit menu. | ||||
| CVE-2020-18035 | 1 Jeesns | 1 Jeesns | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting (XSS) in Jeesns v1.4.2 allows remote attackers to execute arbitrary code by injecting commands into the "CKEditorFuncNum" parameter in the component "CkeditorUploadController.java". | ||||
| CVE-2020-18022 | 1 Qibosoft | 1 Qibocms | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting (XSS) in Qibosoft QiboCMS v7 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information by injecting arbitrary commands in a HTTP request to the "ewebeditor\3.1.1\kindeditor.js" component. | ||||
| CVE-2020-17999 | 1 1234n | 1 Minicms | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via a crafted HTTP request to the component "/mc-admin/post-edit.php". | ||||
| CVE-2020-17891 | 1 Tp-link | 2 Archer C1200, Archer C1200 Firmware | 2024-11-21 | 6.1 Medium |
| TP-Link Archer C1200 firmware version 1.13 Build 2018/01/24 rel.52299 EU has a XSS vulnerability allowing a remote attacker to execute arbitrary code. | ||||
| CVE-2020-17551 | 1 Impresscms | 1 Impresscms | 2024-11-21 | 4.8 Medium |
| ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution. | ||||
| CVE-2020-17542 | 1 Dotcms | 1 Dotcms | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail" comment window of the "/dotAdmin/#/c/workflow" component. | ||||
| CVE-2020-17480 | 1 Tiny | 1 Tinymce | 2024-11-21 | 6.1 Medium |
| TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor. | ||||
| CVE-2020-17476 | 1 Mibew | 1 Messenger | 2024-11-21 | 6.1 Medium |
| Mibew Messenger before 3.2.7 allows XSS via a crafted user name. | ||||
| CVE-2020-17465 | 1 Forgerock | 1 Identity Manager | 2024-11-21 | 6.1 Medium |
| Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. The vulnerability affects versions 6.5.0.4, 6.0.0.6. | ||||
| CVE-2020-17458 | 1 Fabbricadigitale | 1 Multiux | 2024-11-21 | 5.4 Medium |
| A post-authenticated stored XSS was found in MultiUx v.3.1.12.0 via the /multiux/SaveMailbox LastName field. | ||||
| CVE-2020-17457 | 1 Fujitsu | 1 Serverview Remote Management | 2024-11-21 | 5.4 Medium |
| Fujitsu ServerView Suite iRMC before 9.62F allows XSS. An authenticated attacker can store an XSS payload in the PSCU_FILE_INIT field of a Save Configuration XML document. The payload is triggered in the HTTP error response pages. | ||||