Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

17,305 results · Page 253/347
6.1
CVE-2016-10920

The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.

6.1
CVE-2017-18572

The gnucommerce plugin before 1.4.2 for WordPress has XSS.

6.1
CVE-2017-18574

The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.

6.1
CVE-2017-18575

The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues.

6.1
CVE-2018-20982

The media-library-assistant plugin before 2.74 for WordPress has XSS via the Media/Assistant or Settings/Media Library a

6.1
CVE-2008-7321

The tubepress plugin before 1.6.5 for WordPress has XSS.

6.1
CVE-2013-7482

The reflex-gallery plugin before 1.4.3 for WordPress has XSS.

6.1
CVE-2014-10385

The memphis-documents-library plugin before 3.0 for WordPress has XSS via $_REQUEST.

6.1
CVE-2016-10925

The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs.

6.1
CVE-2017-18576

The event-notifier plugin before 1.2.1 for WordPress has XSS via the loading animation.

6.1
CVE-2017-18577

The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.

6.1
CVE-2017-18581

The time-sheets plugin before 1.5.0 for WordPress has XSS via the old timesheet list.

6.1
CVE-2017-18582

The time-sheets plugin before 1.5.2 for WordPress has multiple XSS issues.

6.1
CVE-2018-20983

The wp-retina-2x plugin before 5.2.3 for WordPress has XSS.

6.1
CVE-2014-10391

The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.

6.1
CVE-2014-10392

The cforms2 plugin before 10.2 for WordPress has XSS.

6.1
CVE-2014-10394

The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.

6.1
CVE-2019-15331

The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.

6.1
CVE-2014-10386

The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.

6.1
CVE-2014-10393

The cforms2 plugin before 10.5 for WordPress has XSS.

6.1
CVE-2017-18578

The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS.

6.1
CVE-2017-18579

The corner-ad plugin before 1.0.8 for WordPress has XSS.

6.1
CVE-2019-15327

The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data.

6.1
CVE-2019-15328

The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS.

6.1
CVE-2019-15499

CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute,

6.1
CVE-2019-15476

Former before 4.2.1 has XSS via a checkbox value.

6.1
CVE-2019-15477

Jooby before 1.6.4 has XSS via the default error handler.

6.1
CVE-2019-15481

Kimai v2 before 1.1 has XSS via a timesheet description.

6.1
CVE-2019-15482

selectize-plugin-a11y before 1.1.0 has XSS via the msg field.

6.1
CVE-2019-15483

Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.

6.1
CVE-2019-15484

Bolt before 3.6.10 has XSS via an image's alt or title field.

6.1
CVE-2019-15485

Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.

6.1
CVE-2019-15486

django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.

6.1
CVE-2019-15487

DfE School Experience before v16333-GA has XSS via a teacher training URL.

6.1
CVE-2019-15488

Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.

6.1
CVE-2019-15492

openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.

6.1
CVE-2019-11584

The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or Java

6.1
CVE-2019-11585

The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0

6.1
CVE-2019-11589

The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from ve

6.1
CVE-2019-13422

Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the us

6.1
CVE-2019-5594

An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.

6.1
CVE-2016-6154

The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open r

6.1
CVE-2019-15478

Status Board 1.1.81 has reflected XSS via logic.ts.

6.1
CVE-2019-15489

laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS.

6.1
CVE-2019-15532

CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.

6.1
CVE-2019-15479

Status Board 1.1.81 has reflected XSS via dashboard.ts.

6.1
CVE-2019-15501

Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.

6.1
CVE-2018-18668

GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage t

6.1
CVE-2014-10395

The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.

6.1
CVE-2015-9342

The wp-rollback plugin before 1.2.3 for WordPress has XSS.

Scan for 2019 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started