17,305 vulnerabilities published in 2019
Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that t
CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields
Prospecta Master Data Online (MDO) 2.0 has Stored XSS.
The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5
FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other m
OX App Suite 7.10.0 to 7.10.2 allows XSS.
IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr
IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users
REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data im
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain parameter allows a low-privilege user to
tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting
The give plugin before 2.4.7 for WordPress has XSS via a donor name.
In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS.
An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" func
The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by autho
Domoticz 4.10717 has XSS via item.Name.
The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote atta
LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Ale
The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_e
The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS.
The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.
The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.
The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.
The webp-express plugin before 0.14.8 for WordPress has stored XSS.
The JobCareer theme before 2.5.1 for WordPress has stored XSS.
The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.
Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or
IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2 and IBM Business Process Manager V8.6.0.0 through V8.6.0.0
The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.
An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result i
An input validation and output encoding issue was discovered in the GitLab email notification feature which could result
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unpri
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example,
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor
A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users
The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.
The examapp plugin 1.0 for WordPress has XSS via exam input text fields.
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to access a
In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack throug
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 cont
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall
A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly san
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided i
Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site
Jenkins Dashboard View Plugin 2.11 and earlier did not escape build descriptions, resulting in a cross-site scripting vu
DOM-based cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.10.2 allows remote authenticated attackers to i
The Headway theme before 3.8.9 for WordPress has XSS via the license key field.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started