17,305 vulnerabilities published in 2019
In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page.
Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update
A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute ar
IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability al
4.1.0, 4.1.1, 4.1.2, 4.1.2.3, 4.1.2.6, 4.1.2.7, 4.2.0, 4.2.1, 4.2.2, 5.0.0, 5.0.0.5, 5.0.0.6, 5.0.1, 5.0.1.1, 5.0.1.2, 5
TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administ
The WebARX plugin 1.3.0 for WordPress has unauthenticated stored XSS via the URI or the X-Forwarded-For HTTP header.
The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has
A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inj
The broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL tha
includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for Wor
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or
Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An
S-CMS v1.5 has XSS in tpl.php via the member/member_login.php from parameter.
cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521).
cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524).
cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526).
cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527).
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).
The animate-it plugin before 2.3.4 for WordPress has XSS.
The animate-it plugin before 2.3.5 for WordPress has XSS.
An XSS vulnerability in project list in OpenProject before 9.0.4 and 10.x before 10.0.2 allows remote attackers to injec
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
The liquid-speech-balloon (aka LIQUID SPEECH BALLOON) plugin before 1.0.7 for WordPress allows XSS with Internet Explore
The client-dash (aka Client Dash) plugin 2.1.4 for WordPress allows XSS.
EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter.
The searchterms-tagging-2 plugin through 1.535 for WordPress has XSS via the wp-admin/options-general.php count paramete
The broken-link-manager plugin 0.4.5 for WordPress has XSS via the page parameter in a delURL action.
The incoming-links plugin before 0.9.10b for WordPress has referrers.php XSS via the Referer HTTP header.
prettyPhoto before 3.1.6 has js/jquery.prettyPhoto.js XSS.
b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header.
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[title] parameter to web/polygon/problem/create or web/pol
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[description] parameter to web/admin/problem/create or web
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[sample_input] parameter to web/admin/problem/create or we
laravel-bjyblog 6.1.1 has XSS via a crafted URL.
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: admin/login.html with the parameter username is persis
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][contro
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][action
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][uid] i
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/ with the parameter password is non-persistent
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vuln
Genesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, Clie
Gila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a
A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attac
SonarSource SonarQube before 7.8 has XSS in project links on account/projects.
OX App Suite 7.10.1 and 7.10.2 allows XSS.
There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.
In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like <
Scan for 2019 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started