Vulnerabilities (CVE)

Filtered by CWE-79
Total 35377 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-9299 1 Pixelite 1 Events Manager 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.
CVE-2015-9297 1 Pixelite 1 Events Manager 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The events-manager plugin before 5.6 for WordPress has XSS.
CVE-2015-9296 1 Never5 1 Download Monitor 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
CVE-2015-9295 1 Bestwebsoft 1 Contact Form 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The contact-form-plugin plugin before 3.96 for WordPress has XSS.
CVE-2015-9294 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.
CVE-2015-9293 1 Tipsandtricks-hq 1 All In One Wp Security \& Firewall 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.
CVE-2015-9286 1 Nodebb 1 Nodebb 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.
CVE-2015-9285 1 Esotalk 1 Esotalk 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
esoTalk 1.0.0g4 has XSS via the PATH_INFO to the conversations/ URI.
CVE-2015-9282 1 Grafana 1 Piechart-panel 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote unauthenticated access to the dashboard.
CVE-2015-9281 6 Hpe, Ibm, Linux and 3 more 6 Hp-ux Ipfilter, Aix, Linux Kernel and 3 more 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.
CVE-2015-9279 1 Mailenable 1 Mailenable 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.
CVE-2015-9276 1 Smartertools 1 Smartermail 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
SmarterTools SmarterMail before 13.3.5535 was vulnerable to stored XSS by bypassing the anti-XSS mechanisms. It was possible to run JavaScript code when a victim user opens or replies to the attacker's email, which contained a malicious payload. Therefore, users' passwords could be reset by using an XSS attack, as the password reset page did not need the current password.
CVE-2015-9273 1 Wp-slimstat 1 Slimstat Analytics 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
The wp-slimstat (aka Slimstat Analytics) plugin before 4.1.6.1 for WordPress has XSS via an HTTP Referer header, or via a field associated with JavaScript-based Referer tracking.
CVE-2015-9270 1 Theholidaycalendar 1 Holiday Calendar 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
XSS exists in the the-holiday-calendar plugin before 1.11.3 for WordPress via the thc-month parameter.
CVE-2015-9260 1 Bedita 1 Bedita 2024-11-21 3.5 LOW 5.4 MEDIUM
An issue was discovered in BEdita before 3.7.0. A cross-site scripting (XSS) attack occurs via a crafted pages/showObjects URI, as demonstrated by appending a payload to a pages/showObjects/2/0/0/leafs URI.
CVE-2015-9257 1 Bmc 1 Remedy Action Request System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
BMC Remedy Action Request (AR) System 9.0 before 9.0.00 Service Pack 2 hot fix 1 has persistent XSS.
CVE-2015-9251 2 Jquery, Oracle 47 Jquery, Agile Product Lifecycle Management For Process, Banking Platform and 44 more 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
CVE-2015-9248 1 Skyboxsecurity 1 Skybox Platform 2024-11-21 3.5 LOW 5.4 MEDIUM
An issue was discovered in Skybox Platform before 7.5.201. Stored cross-site scripting vulnerabilities exist in the title, Comments, or Description field to /skyboxview/webskybox/tickets in Change Manager.
CVE-2015-9247 1 Skyboxsecurity 1 Skybox Platform 2024-11-21 3.5 LOW 5.4 MEDIUM
An issue was discovered in Skybox Platform before 7.5.401. Reflected cross-site scripting vulnerabilities exist in /skyboxview/webservice/services/VersionRepositoryWebService via a soapenv:Body element, or in the status parameter to login.html.
CVE-2015-7609 1 Synacor 1 Zimbra Collaboration Suite 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Synacor Zimbra Mail Client 8.6 before 8.6.0 Patch 5 has XSS via the error/warning dialog and email body content in Zimbra.