| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files. |
| A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc. |
| The seefl package v0.1.1 is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability via a malicious filename rendered in a directory listing. |
| The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (XSS) vulnerability in files it serves. |
| In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. |
| A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin. |
| The proj_doc_edit_page.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed when editing the document's page. |
| CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs. |
| ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role. |
| Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter. |
| CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL. |
| Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP. |
| openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21. |
| laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS. |
| Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test. |
| DfE School Experience before v16333-GA has XSS via a teacher training URL. |
| django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline. |
| Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php. |
| Bolt before 3.6.10 has XSS via an image's alt or title field. |
| Bolt before 3.6.10 has XSS via a title that is mishandled in the system log. |