Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

17,305 results · Page 299/347
5.4
CVE-2019-14518

Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that t

5.4
CVE-2018-12101

CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields

5.4
CVE-2018-17790

Prospecta Master Data Online (MDO) 2.0 has Stored XSS.

5.4
CVE-2019-15120

The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.

5.4
CVE-2019-11276

Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5

5.4
CVE-2019-15228

FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other m

5.4
CVE-2019-11522

OX App Suite 7.10.0 to 7.10.2 allows XSS.

5.4
CVE-2019-4120

IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr

5.4
CVE-2019-4482

IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users

5.4
CVE-2019-15127

REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data im

5.4
CVE-2019-13476

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain parameter allows a low-privilege user to

5.4
CVE-2019-15314

tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting

5.4
CVE-2019-15317

The give plugin before 2.4.7 for WordPress has XSS via a donor name.

5.4
CVE-2019-14469

In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS.

5.4
CVE-2019-12386

An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" func

5.4
CVE-2018-20986

The advanced-custom-fields (aka Elliot Condon Advanced Custom Fields) plugin before 5.7.8 for WordPress has XSS by autho

5.4
CVE-2019-15480

Domoticz 4.10717 has XSS via item.Name.

5.4
CVE-2019-8444

The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote atta

5.4
CVE-2019-15230

LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Ale

5.4
CVE-2019-15777

The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_e

5.4
CVE-2019-15778

The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS.

5.4
CVE-2019-15827

The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.

5.4
CVE-2019-15830

The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.

5.4
CVE-2019-15836

The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.

5.4
CVE-2019-15837

The webp-express plugin before 0.14.8 for WordPress has stored XSS.

5.4
CVE-2019-15869

The JobCareer theme before 2.5.1 for WordPress has stored XSS.

5.4
CVE-2019-15870

The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.

5.4
CVE-2019-15814

Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or

5.4
CVE-2019-4149

IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2 and IBM Business Process Manager V8.6.0.0 through V8.6.0.0

5.4
CVE-2018-21014

The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.

5.4
CVE-2019-5467

An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result i

5.4
CVE-2019-5471

An input validation and output encoding issue was discovered in the GitLab email notification feature which could result

5.4
CVE-2019-11548

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unpri

5.4
CVE-2019-16172

LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su

5.4
CVE-2019-16173

LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example,

5.4
CVE-2019-6795

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor

5.4
CVE-2019-16178

A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users

5.4
CVE-2017-18600

The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.

5.4
CVE-2017-18601

The examapp plugin 1.0 for WordPress has XSS via exam input text fields.

5.4
CVE-2019-14726

In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to access a

5.4
CVE-2019-16193

In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack throug

5.4
CVE-2019-16223

WordPress before 5.2.3 allows XSS in post previews by authenticated users.

5.4
CVE-2019-3761

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 cont

5.4
CVE-2019-1262

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall

5.4
CVE-2019-1273

A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly san

5.4
CVE-2019-1305

A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided i

5.4
CVE-2019-10395

Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site

5.4
CVE-2019-10396

Jenkins Dashboard View Plugin 2.11 and earlier did not escape build descriptions, resulting in a cross-site scripting vu

5.4
CVE-2019-5975

DOM-based cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.10.2 allows remote authenticated attackers to i

5.4
CVE-2016-10953

The Headway theme before 3.8.9 for WordPress has XSS via the license key field.

Scan for 2019 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started