Vulnerabilities (CVE)

Filtered by CWE-79
Total 47367 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-7742 1 Joomla 1 Joomla\! 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Joomla! before 3.9.3. A combination of specific web server configurations, in connection with specific file types and browser-side MIME-type sniffing, causes an XSS attack vector.
CVE-2019-7741 1 Joomla 1 Joomla\! 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Joomla! before 3.9.3. Inadequate checks at the Global Configuration helpurl settings allowed stored XSS.
CVE-2019-7740 1 Joomla 1 Joomla\! 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Joomla! before 3.9.3. Inadequate parameter handling in JavaScript code (core.js writeDynaList) could lead to an XSS attack vector.
CVE-2019-7693 1 Axiositalia 1 Registro Elettronico 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Axios Italia Axios RE 1.7.0/7.0.0 devices have XSS via the RELogOff.aspx Error_Parameters parameter. In some situations, the XSS would be on the family.axioscloud.it cloud service; however, the vendor also supports "Sissi in Rete (con server)" for offline operation.
CVE-2019-7687 1 Jio 2 Jmr1140, Jmr1140 Firmware 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
cgi-bin/qcmap_web_cgi on JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices has POST based reflected XSS via the Page parameter. No sanitization is performed for user input data.
CVE-2019-7677 1 Enphase 1 Envoy 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888.
CVE-2019-7671 1 Primasystems 1 Flexair 2026-06-17 3.5 LOW 9.0 CRITICAL
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user, which may allow an attacker to execute arbitrary code in a user’s browser session in context of an affected site.
CVE-2019-7661 1 Phpmywind 1 Phpmywind 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in PHPMyWind 5.5. The method parameter of the data/api/oauth/connect.php page has a reflected Cross-site Scripting (XSS) vulnerability.
CVE-2019-7660 1 Phpmywind 1 Phpmywind 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in PHPMyWind 5.5. The username parameter of the /install/index.php page has a stored Cross-site Scripting (XSS) vulnerability, as demonstrated by admin/login.php.
CVE-2019-7655 1 Wowza 1 Streaming Engine 2026-06-17 3.5 LOW 5.4 MEDIUM
Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.value field in enginemanager/server/serversetup/edit_adv.htm of the Server Setup configuration or the (2) host field in enginemanager/j_spring_security_check of the login form. This issue was resolved in Wowza Streaming Engine 4.8.5.
CVE-2019-7646 1 Control-webpanel 1 Webpanel 2026-06-17 3.5 LOW 4.8 MEDIUM
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via the add_package module parameter.
CVE-2019-7634 1 Ifrn 1 Sistema Unificado De Administracao Publica 2026-06-17 3.5 LOW 5.4 MEDIUM
SUAP V2 allows XSS during the update of user information.
CVE-2019-7621 1 Elastic 1 Kibana 2026-06-17 3.5 LOW 5.4 MEDIUM
Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim�s browser.
CVE-2019-7608 1 Elastic 1 Kibana 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
CVE-2019-7567 1 Bijiadao 1 Waimai Super Cms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Waimai Super Cms 20150505. admin.php?m=Member&a=adminaddsave has XSS via the username or password parameter.
CVE-2019-7554 1 Api Based Travel Booking Project 1 Api Based Travel Booking 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in PHP Scripts Mall API Based Travel Booking 3.4.7. There is Reflected XSS via the flight-results.php d2 parameter.
CVE-2019-7553 1 Chartered Accountant \ 1 Auditor Website Project 2026-06-17 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name field.
CVE-2019-7552 1 Investment Mlm Software Project 1 Investment Mlm Software 2026-06-17 3.5 LOW 5.4 MEDIUM
An issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Section. This is due to lack of sanitization in the Edit Name section.
CVE-2019-7551 1 Cantemo 1 Portal 2026-06-17 6.0 MEDIUM 9.0 CRITICAL
Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would enable performing actions as users, including administrative users. This could enable account creation and deletion as well as deletion of information contained within the app.
CVE-2019-7547 1 Topnew 1 Sidu 2026-06-17 3.5 LOW 4.8 MEDIUM
An issue was discovered in SIDU 6.0. Because the database name is not strictly filtered, the attacker can insert a name containing an XSS Payload, leading to stored XSS.