Vulnerabilities (CVE)

Filtered by CWE-79
Total 47376 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-21506 1 Waimai Super Cms Project 1 Waimai Super Cms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php?m=Config&a=add.
CVE-2020-21505 1 Waimai Super Cms Project 1 Waimai Super Cms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php/Link/addsave.
CVE-2020-21504 1 Waimai Super Cms Project 1 Waimai Super Cms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php?&m=Public&a=login.
CVE-2020-21496 1 Xiuno 1 Xiunobbs 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitebrief parameter.
CVE-2020-21495 1 Xiuno 1 Xiunobbs 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitename parameter.
CVE-2020-21494 1 Xiuno 1 Xiunobbs 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the component install\install.sql of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via changing the doctype value to 0.
CVE-2020-21487 1 Netgate 2 Pfsense, Pfsense Acme Package 2026-06-17 N/A 9.6 CRITICAL
Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.
CVE-2020-21485 1 Alluxio 1 Alluxio 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path parameter in the browse board component.
CVE-2020-21482 1 Rgcms Project 1 Rgcms 2026-06-17 3.5 LOW 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in RGCMS v1.06 allows attackers to obtain the administrator's cookie via a crafted payload in the Name field under the Message Board module
CVE-2020-21434 1 Maccms 1 Maccms 2026-06-17 3.5 LOW 5.4 MEDIUM
Maccms 10 contains a cross-site scripting (XSS) vulnerability in the Editing function under the Member module. This vulnerability is exploited via a crafted payload in the nickname text field.
CVE-2020-21387 1 Maccms 1 Maccms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and escalate privileges via a crafted payload.
CVE-2020-21362 1 Maccms 1 Maccms 2026-06-17 3.5 LOW 5.4 MEDIUM
A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arbitrary web scripts or HTML via the 'wd' parameter.
CVE-2020-21357 1 Popojicms 1 Popojicms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
A stored cross site scripting (XSS) vulnerability in /admin.php?mod=user&act=addnew of PopojiCMS 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the E-Mail field.
CVE-2020-21353 1 Get-simple 1 Getsimplecms 2026-06-17 3.5 LOW 5.4 MEDIUM
A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets module.
CVE-2020-21345 1 Halo 1 Halo 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Halo 1.1.3 via post publish components in the manage panel, which lets a remote malicious user execute arbitrary code.
CVE-2020-21333 1 Publiccms 1 Publiccms 2026-06-17 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case.
CVE-2020-21316 1 Zrlog 1 Zrlog 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain access to the admin panel.
CVE-2020-21268 1 Easycorp 1 Zentao 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parameter.
CVE-2020-21266 1 Broadleafcommerce 1 Broadleaf Commerce 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Broadleaf Commerce 5.1.14-GA is affected by cross-site scripting (XSS) due to a slow HTTP post vulnerability.
CVE-2020-21246 1 Yiicms Project 1 Yiicms 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in YiiCMS v.1.0 allows a remote attacker to execute arbitrary code via the news function.