Vulnerabilities (CVE)

Filtered by CWE-79
Total 35377 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-4454 1 Tiki 1 Tiki 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting vulnerabilities in Tiki 8.0 RC1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) tiki-remind_password.php, (2) tiki-index.php, (3) tiki-login_scr.php, or (4) tiki-index.
CVE-2011-4336 1 Tiki 1 Tikiwiki Cms\/groupware 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.
CVE-2011-4095 1 Jara Project 1 Jara 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Jara 1.6 has an XSS vulnerability
CVE-2011-4090 1 S9y 1 Serendipity 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.
CVE-2011-3656 1 Mozilla 1 Firefox 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.
CVE-2011-3642 1 Flowplayer 1 Flowplayer Flash 2024-11-21 6.8 MEDIUM 9.6 CRITICAL
Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin.
CVE-2011-3622 1 Phorum 1 Phorum 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A Cross-Site Scripting (XSS) vulnerability exists in the admin login screen in Phorum before 5.2.18.
CVE-2011-3610 1 S9y 1 Serendipity Event Freetag 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A Cross-site Scripting (XSS) vulnerability exists in the Serendipity freetag plugin before 3.30 in the tagcloud parameter to plugins/serendipity_event_freetag/tagcloud.swf.
CVE-2011-3606 1 Redhat 1 Jboss Application Server 2024-11-21 3.5 LOW 5.4 MEDIUM
A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user, with the administrator privilege, to visit it, which would lead into the DOM environment modification and arbitrary HTML or web script execution.
CVE-2011-3595 1 Joomla 1 Joomla\! 2024-11-21 3.5 LOW 5.4 MEDIUM
Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.
CVE-2011-3373 1 Drupal 1 Views Builk Operations 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially-crafted URL that could lead to cross-site scripting (XSS) attack.
CVE-2011-3370 1 Status 1 Statusnet 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
statusnet before 0.9.9 has XSS
CVE-2011-3352 1 Ziku 1 Zikula 2024-11-21 3.5 LOW 4.8 MEDIUM
Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script code in the context of the affected website.
CVE-2011-3202 1 Jcow 1 Jcow Cms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A Cross-Site Scripting (XSS) vulnerability exists in the g parameter to index.php in Jcow CMS 4.2 and earlier.
CVE-2011-3183 1 Concretecms 1 Concrete Cms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier.
CVE-2011-2935 1 Elgg 1 Elgg 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Elgg through 1.7.10 has XSS
CVE-2011-2714 1 Drupal 2 Data, Drupal 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.
CVE-2011-2706 1 Snewscms 1 Snews 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.
CVE-2011-2670 1 Mozilla 1 Firefox 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets
CVE-2011-2499 1 Mambo-foundation 1 Mambo Cms 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Mambo CMS through 4.6.5 has multiple XSS.