Vulnerabilities (CVE)

Filtered by CWE-79
Total 37574 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-9056 1 Periscopeholdings 1 Buyspeed 2024-11-21 3.5 LOW 3.9 LOW
Periscope BuySpeed version 14.5 is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to store arbitrary JavaScript within the application. This JavaScript is subsequently displayed by the application without sanitization and is executed in the browser of the user, which could possibly cause website redirection, session hijacking, or information disclosure. This vulnerability has been patched in BuySpeed version 15.3.
CVE-2020-9055 1 Versiant 1 Lynx Customer Service Portal 2024-11-21 3.5 LOW 3.9 LOW
Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malicious JavaScript that is stored and displayed to the end user. This could lead to website redirects, session cookie hijacking, or information disclosure.
CVE-2020-9038 1 Joplin Project 1 Joplin 2024-11-21 3.5 LOW 5.4 MEDIUM
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
CVE-2020-9036 1 Jeedom 1 Jeedom 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Jeedom through 4.0.38 allows XSS.
CVE-2020-9028 1 Microchip 10 Syncserver S100, Syncserver S100 Firmware, Syncserver S200 and 7 more 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on the "User Creation, Deletion and Password Maintenance" screen (when creating a new user).
CVE-2020-9025 1 Iteris 2 Vantage Velocity, Vantage Velocity Firmware 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Iteris Vantage Velocity Field Unit 2.4.2 devices have multiple stored XSS issues in all parameters of the Start Data Viewer feature of the /cgi-bin/loaddata.py script.
CVE-2020-9022 1 Cambiumnetworks 8 Xh2-120, Xh2-120 Firmware, Xr2436 and 5 more 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered on Xirrus XR520, XR620, XR2436, and XH2-120 devices. The cgi-bin/ViewPage.cgi user parameter allows XSS.
CVE-2020-9019 1 Wpjobboard 1 Wpjobboard 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The WPJobBoard plugin 5.5.3 for WordPress allows Persistent XSS via the Add Job form, as demonstrated by title and Description.
CVE-2020-9016 1 Dolibarr 1 Dolibarr Erp\/crm 2024-11-21 3.5 LOW 5.4 MEDIUM
Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.
CVE-2020-9012 1 Gluu 1 Gluu Server 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the Import People functionality in Gluu Identity Configuration 4.0 allows remote attackers to inject arbitrary web script or HTML via the filename parameter.
CVE-2020-9008 1 Blackboard 1 Blackboard Learn 2024-11-21 3.5 LOW 5.4 MEDIUM
Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile editor.
CVE-2020-9007 1 Codologic 1 Codoforum 2024-11-21 3.5 LOW 5.4 MEDIUM
Codoforum 4.8.8 allows self-XSS via the title of a new topic.
CVE-2020-9003 1 Machothemes 1 Modula Image Gallery 2024-11-21 3.5 LOW 5.4 MEDIUM
A stored XSS vulnerability exists in the Modula Image Gallery plugin before 2.2.5 for WordPress. Successful exploitation of this vulnerability would allow an authenticated low-privileged user to inject arbitrary JavaScript code that is viewed by other users.
CVE-2020-8985 1 Zend 1 Zendto 2024-11-21 6.8 MEDIUM 8.8 HIGH
ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.
CVE-2020-8981 1 Mantisbt 1 Source Integration 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability was discovered in the Source Integration plugin before 1.6.2 and 2.x before 2.3.1 for MantisBT. The repo_delete.php Delete Repository page allows execution of arbitrary code via a repo name (if CSP settings permit it). This is related to CVE-2018-16362.
CVE-2020-8966 1 Tiki 1 Tikiwiki Cms\/groupware 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows malicious users to cause the injection of malicious code fragments (scripts) into a legitimate web page.
CVE-2020-8960 1 Westerndigital 1 Mycloud.com 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Western Digital mycloud.com before Web Version 2.2.0-134 allows XSS.
CVE-2020-8952 1 Fiserv 1 Accurate Reconciliation 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the logout.jsp timeOut parameter.
CVE-2020-8951 1 Fiserv 1 Accurate Reconciliation 2024-11-21 3.5 LOW 5.4 MEDIUM
Fiserv Accurate Reconciliation 2.19.0, fixed in 3.0.0 or higher, allows XSS via the Source or Destination field of the Configuration Manager (Configuration Parameter Translation) page.
CVE-2020-8923 1 Dart 1 Dart Software Development Kit 2024-11-21 4.3 MEDIUM 5.4 MEDIUM
An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM Clobbering techniques to skip the sanitization and inject custom html/javascript (XSS). Mitigation: update your Dart SDK to 2.7.2, and 2.8.0-dev.17.0 for the dev version. If you cannot update, we recommend you review the way you use the affected APIs, and pay special attention to cases where user-provided data is used to populate DOM nodes. Consider using Element.innerText or Node.text to populate DOM elements.