Vulnerabilities (CVE)

Filtered by CWE-79
Total 47436 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-28956 1 Sugarcrm 1 Sugarcrm 2026-06-17 3.5 LOW 5.4 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the Sales module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the primary address state or alternate address state input fields.
CVE-2020-28955 1 Sugarcrm 1 Sugarcrm 2026-06-17 3.5 LOW 5.4 MEDIUM
SugarCRM v6.5.18 was discovered to contain a cross-site scripting (XSS) vulnerability in the Create Employee module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the First Name or Last Name input fields.
CVE-2020-28945 1 Open-xchange 1 Open-xchange Appsuite 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as ![](http://onerror=Function.constructor, in a Notes item.
CVE-2020-28938 1 Openclinic Project 1 Openclinic 2026-06-17 3.5 LOW 5.4 MEDIUM
OpenClinic version 0.8.2 is affected by a stored XSS vulnerability in lib/Check.php that allows users of the application to force actions on behalf of other users.
CVE-2020-28930 1 Epson 2 Eps Tse Server 8, Eps Tse Server 8 Firmware 2026-06-17 3.5 LOW 5.4 MEDIUM
A Cross-Site Scripting (XSS) issue in the 'update user' and 'delete user' functionalities in settings/users.php in EPSON EPS TSE Server 8 (21.0.11) allows an authenticated attacker to inject a JavaScript payload in the user management page that is executed by an administrator.
CVE-2020-28927 1 Magicpin 1 Magicpin 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
There is a Stored XSS in Magicpin v2.1 in the User Registration section. Each time an admin visits the manage user section from the admin panel, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.
CVE-2020-28919 1 Checkmk 1 Checkmk 2026-06-17 3.5 LOW 5.4 MEDIUM
A stored cross site scripting (XSS) vulnerability in Checkmk 1.6.0x prior to 1.6.0p19 allows an authenticated remote attacker to inject arbitrary JavaScript via a javascript: URL in a view title.
CVE-2020-28903 1 Nagios 1 Fusion 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS.
CVE-2020-28849 1 Churchcrm 1 Churchcrm 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in ChurchCRM version 4.2.1, allows remote attckers to execute arbitrary code and gain sensitive information via crafted payload in Add New Deposit field in View All Deposit module.
CVE-2020-28847 1 Valine.js 1 Valine 2026-06-17 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in xCss Valine v1.4.14 via the nick parameter to /classes/Comment.
CVE-2020-28722 1 Deskpro 1 Deskpro 2026-06-17 3.5 LOW 5.4 MEDIUM
Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templates.
CVE-2020-28717 1 Kindsoft 1 Kindeditor 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in content1 parameter in demo.jsp in kindsoft kindeditor version 4.1.12, allows attackers to execute arbitrary code.
CVE-2020-28650 1 Wpbakery 1 Page Builder 2026-06-17 3.5 LOW 6.4 MEDIUM
The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard WordPress XSS protection mechanism for the Author and Contributor roles.
CVE-2020-28647 1 Progress 1 Moveit Transfer 2026-06-17 3.5 LOW 5.4 MEDIUM
In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser (XSS).
CVE-2020-28487 1 Visjs 1 Vis-timeline 2026-06-17 6.0 MEDIUM 6.8 MEDIUM
This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application.
CVE-2020-28470 1 Scully 1 Scully 2026-06-17 4.3 MEDIUM 7.3 HIGH
This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.
CVE-2020-28459 1 Markdown-it-decorate Project 1 Markdown-it-decorate 2026-06-17 N/A 7.3 HIGH
This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.
CVE-2020-28457 1 S-cart 1 S-cart 2026-06-17 3.5 LOW 7.2 HIGH
This affects the package s-cart/core before 4.4. The search functionality of the admin dashboard in core/src/Admin/Controllers/AdminOrderController.phpindex is vulnerable to XSS.
CVE-2020-28456 1 S-cart 1 S-cart 2026-06-17 4.3 MEDIUM 7.3 HIGH
The package s-cart/core before 4.4 are vulnerable to Cross-site Scripting (XSS) via the admin panel.
CVE-2020-28455 1 Markdown-it-toc Project 1 Markdown-it-toc 2026-06-17 N/A 7.3 HIGH
This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.