Total
35377 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-9299 | 1 Pixelite | 1 Events Manager | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS. | |||||
CVE-2015-9297 | 1 Pixelite | 1 Events Manager | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The events-manager plugin before 5.6 for WordPress has XSS. | |||||
CVE-2015-9296 | 1 Never5 | 1 Download Monitor | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg. | |||||
CVE-2015-9295 | 1 Bestwebsoft | 1 Contact Form | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The contact-form-plugin plugin before 3.96 for WordPress has XSS. | |||||
CVE-2015-9294 | 1 Tipsandtricks-hq | 1 All In One Wp Security \& Firewall | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances. | |||||
CVE-2015-9293 | 1 Tipsandtricks-hq | 1 All In One Wp Security \& Firewall | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature. | |||||
CVE-2015-9286 | 1 Nodebb | 1 Nodebb | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS. | |||||
CVE-2015-9285 | 1 Esotalk | 1 Esotalk | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
esoTalk 1.0.0g4 has XSS via the PATH_INFO to the conversations/ URI. | |||||
CVE-2015-9282 | 1 Grafana | 1 Piechart-panel | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote unauthenticated access to the dashboard. | |||||
CVE-2015-9281 | 6 Hpe, Ibm, Linux and 3 more | 6 Hp-ux Ipfilter, Aix, Linux Kernel and 3 more | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page. | |||||
CVE-2015-9279 | 1 Mailenable | 1 Mailenable | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message. | |||||
CVE-2015-9276 | 1 Smartertools | 1 Smartermail | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
SmarterTools SmarterMail before 13.3.5535 was vulnerable to stored XSS by bypassing the anti-XSS mechanisms. It was possible to run JavaScript code when a victim user opens or replies to the attacker's email, which contained a malicious payload. Therefore, users' passwords could be reset by using an XSS attack, as the password reset page did not need the current password. | |||||
CVE-2015-9273 | 1 Wp-slimstat | 1 Slimstat Analytics | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
The wp-slimstat (aka Slimstat Analytics) plugin before 4.1.6.1 for WordPress has XSS via an HTTP Referer header, or via a field associated with JavaScript-based Referer tracking. | |||||
CVE-2015-9270 | 1 Theholidaycalendar | 1 Holiday Calendar | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
XSS exists in the the-holiday-calendar plugin before 1.11.3 for WordPress via the thc-month parameter. | |||||
CVE-2015-9260 | 1 Bedita | 1 Bedita | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in BEdita before 3.7.0. A cross-site scripting (XSS) attack occurs via a crafted pages/showObjects URI, as demonstrated by appending a payload to a pages/showObjects/2/0/0/leafs URI. | |||||
CVE-2015-9257 | 1 Bmc | 1 Remedy Action Request System | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
BMC Remedy Action Request (AR) System 9.0 before 9.0.00 Service Pack 2 hot fix 1 has persistent XSS. | |||||
CVE-2015-9251 | 2 Jquery, Oracle | 47 Jquery, Agile Product Lifecycle Management For Process, Banking Platform and 44 more | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. | |||||
CVE-2015-9248 | 1 Skyboxsecurity | 1 Skybox Platform | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in Skybox Platform before 7.5.201. Stored cross-site scripting vulnerabilities exist in the title, Comments, or Description field to /skyboxview/webskybox/tickets in Change Manager. | |||||
CVE-2015-9247 | 1 Skyboxsecurity | 1 Skybox Platform | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in Skybox Platform before 7.5.401. Reflected cross-site scripting vulnerabilities exist in /skyboxview/webservice/services/VersionRepositoryWebService via a soapenv:Body element, or in the status parameter to login.html. | |||||
CVE-2015-7609 | 1 Synacor | 1 Zimbra Collaboration Suite | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Synacor Zimbra Mail Client 8.6 before 8.6.0 Patch 5 has XSS via the error/warning dialog and email body content in Zimbra. |