Vulnerabilities (CVE)

Filtered by CWE-79
Total 47370 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-9955 1 Zyxel 42 Atp200, Atp200 Firmware, Atp500 and 39 more 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.
CVE-2019-9925 1 S-cms 1 S-cms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
S-CMS PHP v1.0 has XSS in 4.edu.php via the S_id parameter.
CVE-2019-9919 1 Harmistechnology 1 Je Messenger 2026-06-17 3.5 LOW 5.4 MEDIUM
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a way that JavaScript gets executed on the side of the receiving user when the message is opened, aka XSS.
CVE-2019-9914 1 Yop-poll 1 Yop-poll 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.
CVE-2019-9913 1 3cx 1 Live Chat 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.
CVE-2019-9912 1 Codecabin 1 Wp Go Maps 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.
CVE-2019-9911 1 Nextscripts 1 Social Networks Auto Poster 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The social-networks-auto-poster-facebook-twitter-g plugin before 4.2.8 for WordPress has wp-admin/admin.php?page=nxssnap-reposter&action=edit item XSS.
CVE-2019-9910 1 King-theme 1 Kingcomposer 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The kingcomposer plugin 2.7.6 for WordPress has wp-admin/admin.php?page=kc-mapper id XSS.
CVE-2019-9909 1 Givewp 1 Givewp 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS.
CVE-2019-9908 1 Hivewebstudios 1 Font Organizer 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The font-organizer plugin 2.1.1 for WordPress has wp-admin/options-general.php manage_font_id XSS.
CVE-2019-9844 2 Fedoraproject, Khanacademy 2 Fedora, Simple-markdown 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.
CVE-2019-9841 1 Vestacp 1 Control Panel 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL.
CVE-2019-9839 1 Vfront 1 Vfront 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
VFront 0.99.5 has Reflected XSS via the admin/menu_registri.php descrizione_g parameter or the admin/sync_reg_tab.php azzera parameter.
CVE-2019-9838 1 Vfront 1 Vfront 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
VFront 0.99.5 has stored XSS via the admin/sync_reg_tab.php azzera parameter, which is mishandled during admin/error_log.php rendering.
CVE-2019-9834 1 Netdata 1 Netdata 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection. Successful exploitation will allow attacker-supplied HTML to run in the context of the affected browser, potentially allowing the attacker to steal authentication credentials or to control how the site is rendered to the user. NOTE: the vendor disputes the risk because there is a clear warning next to the button for importing a snapshot
CVE-2019-9765 1 Blog Mini Project 1 Blog Mini 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
In Blog_mini 1.0, XSS exists via the author name of a comment reply in the app/main/views.py articleDetails() function, related to app/templates/_article_comments.html.
CVE-2019-9763 1 Openfind 1 Mail2000 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Openfind Mail2000 6.0 and 7.0 Webmail. XSS can occur via an '<object data="data:text/html' substring in an e-mail message (The vendor subsequently patched this).
CVE-2019-9758 1 Labkey 1 Labkey Server 2026-06-17 3.5 LOW 5.4 MEDIUM
An issue was discovered in LabKey Server 19.1.0. The display name of a user is vulnerable to stored XSS that can execute on administrators from security/permissions.view, security/addUsers.view, or wiki/Administration/page.view in the admin panel, leading to privilege escalation.
CVE-2019-9752 2 Opensuse, Otrs 3 Backports Sle, Leap, Otrs 2026-06-17 3.5 LOW 5.4 MEDIUM
An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4. An attacker who is logged into OTRS as an agent or a customer user may upload a carefully crafted resource in order to cause execution of JavaScript in the context of OTRS. This is related to Content-type mishandling in Kernel/Modules/PictureUpload.pm.
CVE-2019-9751 1 Otrs 1 Otrs 2026-06-17 3.5 LOW 4.8 MEDIUM
An issue was discovered in Open Ticket Request System (OTRS) 6.x before 6.0.17 and 7.x before 7.0.5. An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the context of OTRS. This is related to Kernel/Output/Template/Document.pm.