17,305 vulnerabilities published in 2019
openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.
The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or Java
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0
The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from ve
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the us
An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open r
Status Board 1.1.81 has reflected XSS via logic.ts.
laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS.
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
Status Board 1.1.81 has reflected XSS via dashboard.ts.
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage t
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
The wp-rollback plugin before 1.2.3 for WordPress has XSS.
The cp-polls plugin before 1.0.5 for WordPress has XSS.
The wp-plotly plugin before 1.0.3 for WordPress has XSS by authors.
The ckeditor-for-wordpress plugin before 4.5.3.1 for WordPress has reflected XSS in the "built-in (old)" file browser.
The check-email plugin before 0.5.2 for WordPress has XSS.
The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues.
The anycomment plugin before 0.0.33 for WordPress has XSS.
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the man
The ultimate-faqs plugin before 1.8.22 for WordPress has XSS.
The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS.
The feed-them-social plugin before 1.7.0 for WordPress has reflected XSS in the Facebook Feeds load more button.
The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option.
The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.
In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db p
public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and
The redirection plugin before 2.2.9 for WordPress has XSS in the admin menu, a different issue than CVE-2011-4562.
The redirection plugin before 2.2.12 for WordPress has XSS, a different issue than CVE-2011-4562.
The sharebar plugin before 1.2.2 for WordPress has XSS, a different issue than CVE-2013-3491.
The two-factor-authentication plugin before 1.1.10 for WordPress has XSS in the admin area.
The wp-vipergb plugin before 1.3.16 for WordPress has XSS via add_query_arg() and remove_query_arg(), a different issue
The akismet plugin before 3.1.5 for WordPress has XSS.
The feedwordpress plugin before 2015.0514 for WordPress has XSS via add_query_arg() and remove_query_arg().
The updraftplus plugin before 1.9.64 for WordPress has XSS via add_query_arg() and remove_query_arg().
The Related Posts plugin before 1.8.2 for WordPress has XSS via add_query_arg() and remove_query_arg().
The Post Connector plugin before 1.0.4 for WordPress has XSS via add_query_arg() and remove_query_arg().
iThemes Exchange before 1.12.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
2Checkout Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Authorize.net Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
Custom URL Tracking Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_
Easy Canadian Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_
Easy EU Value Added (VAT) Taxes Add-on for iThemes Exchange before 1.2.0 for WordPress has XSS via add_query_arg() and r
The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a
The my-calendar plugin before 3.1.10 for WordPress has XSS.
Easy US Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started