17,305 vulnerabilities published in 2019
The supportflow plugin before 0.7 for WordPress has XSS via a ticket excerpt.
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document
The CRM Plugin before 4.2.4 for Redmine allows XSS via crafted vCard data.
The Brafton plugin before 3.4.8 for WordPress has XSS via the wp-admin/admin.php?page=BraftonArticleLoader tab parameter
An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerab
An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown
OpenEMR v5.0.1-6 allows XSS.
The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has reflected XSS via the skin parameter.
The safe-editor plugin before 1.2 for WordPress has no se_save authentication, with resultant XSS.
The fossura-tag-miner plugin before 1.1.5 for WordPress has XSS.
The kento-post-view-counter plugin through 2.8 for WordPress has XSS via kento_pvc_geo.
The kento-post-view-counter plugin through 2.8 for WordPress has stored XSS via kento_pvc_numbers_lang, kento_pvc_today_
The echosign plugin before 1.2 for WordPress has XSS via the inc.php page parameter.
The echosign plugin before 1.2 for WordPress has XSS via the templates/add_templates.php id parameter.
The tweet-wheel plugin before 1.0.3.3 for WordPress has XSS via consumer_key, consumer_secret, access_token, and access_
The persian-woocommerce-sms plugin before 3.3.4 for WordPress has ps_sms_numbers XSS.
The leenkme plugin before 2.6.0 for WordPress has stored XSS via facebook_message, facebook_linkname, facebook_caption,
The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.
The music-store plugin before 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports from
A reflected Cross-site scripting (XSS) vulnerability in HRworks V 1.16.1 allows remote attackers to inject arbitrary web
IBM Cloud Application Performance Management 8.1.4 could allow a remote attacker to hijack the clicking action of the vi
SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.
SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 chara
The Truemag theme 2016 Q2 for WordPress has XSS via the s parameter.
A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker t
An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filt
An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly escape output on error, leading to ref
An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to a
An issue was discovered in PRiSE adAS 1.7.0. Certificate data are not properly escaped. This leads to XSS when submittin
An issue was discovered in PRiSE adAS 1.7.0. The newentityID parameter is not properly escaped, leading to a reflected X
The relevant plugin before 1.0.8 for WordPress has XSS.
The quotes-and-tips plugin before 1.20 for WordPress has XSS.
The mtouch-quiz plugin before 3.1.3 for WordPress has XSS via the quiz parameter during a Quiz Manage operation.
The yawpp plugin through 1.2.2 for WordPress has XSS via the field1 parameter.
The ocim-mp3 plugin through 2016-03-07 for WordPress has wp-content/plugins/ocim-mp3/source/pages.php?id= XSS.
The Goodnews theme through 2016-02-28 for WordPress has XSS via the s parameter.
The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.
The instalinker plugin before 1.1.2 for WordPress has includes/instalinker-admin-preview.php?client_id= XSS.
The wp-listings plugin before 2.0.2 for WordPress has includes/views/single-listing.php XSS.
The auto-thickbox-plus plugin through 1.9 for WordPress has wp-content/plugins/auto-thickbox-plus/download.min.php?file=
The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_location XSS.
The neuvoo-jobroll plugin 2.0 for WordPress has neuvoo_keywords XSS.
The wp-piwik plugin before 1.0.5 for WordPress has XSS.
The xpinner-lite plugin through 2.2 for WordPress has xpinner-lite.php XSS.
On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to
On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE:
An issue was discovered in Mautic 2.13.1. It has Stored XSS via the company name field.
TuziCMS 2.0.6 has XSS via the PATH_INFO to a group URI, as demonstrated by index.php/article/group/id/2/.
An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1
admin/infolist_add.php in PHPMyWind 5.6 has stored XSS.
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started