17,305 vulnerabilities published in 2019
The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newslette
The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity
The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows X
The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS.
A remote multiple multiple cross-site vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.
The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript
The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.
The ultimate-member plugin before 2.0.54 for WordPress has XSS.
The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
When creating a module in SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.1, 4.2, 4.3, it
The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall
A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages. An
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by cross-site scripting vulnerability (XSS). Due t
Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that t
CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields
Prospecta Master Data Online (MDO) 2.0 has Stored XSS.
The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5
FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other m
OX App Suite 7.10.0 to 7.10.2 allows XSS.
IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr
IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users
REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data im
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain parameter allows a low-privilege user to
tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting
The give plugin before 2.4.7 for WordPress has XSS via a donor name.
In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS.
An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" func
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by autho
Domoticz 4.10717 has XSS via item.Name.
The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote atta
LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Ale
The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_e
The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS.
The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.
The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.
The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.
The webp-express plugin before 0.14.8 for WordPress has stored XSS.
The JobCareer theme before 2.5.1 for WordPress has stored XSS.
The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.
Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or
IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2 and IBM Business Process Manager V8.6.0.0 through V8.6.0.0
The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.
An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result i
An input validation and output encoding issue was discovered in the GitLab email notification feature which could result
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unpri
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example,
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started