Search Results (43126 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-15487 1 Schoolexperience 1 Department For Education School Experience 2024-11-21 N/A
DfE School Experience before v16333-GA has XSS via a teacher training URL.
CVE-2019-15486 1 Django Js Reverse Project 1 Django Js Reserve 2024-11-21 N/A
django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.
CVE-2019-15485 1 Boltcms 1 Bolt 2024-11-21 N/A
Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.
CVE-2019-15484 1 Boltcms 1 Bolt 2024-11-21 N/A
Bolt before 3.6.10 has XSS via an image's alt or title field.
CVE-2019-15483 1 Boltcms 1 Bolt 2024-11-21 N/A
Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.
CVE-2019-15482 1 Selectize-plugin-a11y Project 1 Selectize-plugin-a11y 2024-11-21 N/A
selectize-plugin-a11y before 1.1.0 has XSS via the msg field.
CVE-2019-15481 1 Kimai 1 Kimai 2 2024-11-21 N/A
Kimai v2 before 1.1 has XSS via a timesheet description.
CVE-2019-15480 1 Domoticz 1 Domoticz 2024-11-21 N/A
Domoticz 4.10717 has XSS via item.Name.
CVE-2019-15479 1 Status Board Project 1 Status Board 2024-11-21 N/A
Status Board 1.1.81 has reflected XSS via dashboard.ts.
CVE-2019-15478 1 Status Board Project 1 Status Board 2024-11-21 N/A
Status Board 1.1.81 has reflected XSS via logic.ts.
CVE-2019-15477 1 Jooby 1 Jooby 2024-11-21 N/A
Jooby before 1.6.4 has XSS via the default error handler.
CVE-2019-15476 1 Former Project 1 Former 2024-11-21 N/A
Former before 4.2.1 has XSS via a checkbox value.
CVE-2019-15331 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2024-11-21 N/A
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
CVE-2019-15328 1 Codection 1 Import Users From Csv With Meta 2024-11-21 N/A
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.
CVE-2019-15327 1 Codection 1 Import Users From Csv With Meta 2024-11-21 N/A
The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.
CVE-2019-15317 1 Givewp 1 Givewp 2024-11-21 N/A
The give plugin before 2.4.7 for WordPress has XSS via a donor name.
CVE-2019-15314 1 Tiki 1 Tikiwiki Cms\/groupware 2024-11-21 N/A
tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting a tiki/tiki-download_file.php?display&fileId= URI.
CVE-2019-15313 1 Zimbra 1 Collaboration Server 2024-11-21 6.1 Medium
In Zimbra Collaboration before 8.8.15 Patch 1, there is a non-persistent XSS vulnerability.
CVE-2019-15278 1 Cisco 2 Finesse, Unified Contact Center Express 2024-11-21 6.1 Medium
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to bypass authorization and access sensitive information related to the device. The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could exploit this vulnerability by submitting a crafted URL. A successful exploit could allow the attacker to gain unauthorized access to sensitive information.
CVE-2019-15233 1 Oldstreetsolutions 1 Live Input Macros 2024-11-21 6.1 Medium
The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of the Administrator Session Cookie.