Vulnerabilities (CVE)

Filtered by CWE-79
Total 47364 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-16216 1 Zulip 1 Zulip Server 2026-06-17 3.5 LOW 5.4 MEDIUM
Zulip server before 2.0.5 incompletely validated the MIME types of uploaded files. A user who is logged into the server could upload files of certain types to mount a stored cross-site scripting attack on other logged-in users. On a Zulip server using the default local uploads backend, the attack is only effective against browsers lacking support for Content-Security-Policy such as Internet Explorer 11. On a Zulip server using the S3 uploads backend, the attack is confined to the origin of the configured S3 uploads hostname and cannot reach the Zulip server itself.
CVE-2019-16197 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.
CVE-2019-16195 1 Centreon 1 Centreon 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields.
CVE-2019-16193 1 Esri 1 Arcgis Enterprise 2026-06-17 3.5 LOW 5.4 MEDIUM
In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.
CVE-2019-16182 1 Limesurvey 1 Limesurvey 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to inject arbitrary web script or HTML via extensions of uploaded files.
CVE-2019-16178 1 Limesurvey 1 Limesurvey 2026-06-17 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users with correct permissions to inject arbitrary web script or HTML via titles of admin box buttons on the home page.
CVE-2019-16173 1 Limesurvey 1 Limesurvey 2026-06-17 3.5 LOW 5.4 MEDIUM
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,
CVE-2019-16172 1 Limesurvey 1 Limesurvey 2026-06-17 3.5 LOW 5.4 MEDIUM
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript that is mishandled upon group deletion.
CVE-2019-16171 1 Jetbrains 1 Youtrack 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page.
CVE-2019-16156 1 Fortinet 1 Fortiweb 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An Improper Neutralization of Input vulnerability in the Anomaly Detection Parameter Name in Fortinet FortiWeb 6.0.5, 6.2.0, and 6.1.1 may allow a remote unauthenticated attacker to perform a Cross Site Scripting attack (XSS).
CVE-2019-16154 1 Fortinet 1 Fortiauthenticator 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page.
CVE-2019-16151 1 Fortinet 1 Fortios 2026-06-17 N/A 4.7 MEDIUM
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker to either redirect users to malicious websites via a crafted "Host" header or to execute JavaScript code in the victim's browser context. This happens when the FortiGate has web filtering and category override enabled/configured.
CVE-2019-16149 1 Fortinet 1 Forticlientems 2026-06-17 N/A 5.5 MEDIUM
An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized code by injecting malicious payload in the user profile of a FortiClient instance being managed by the vulnerable system.
CVE-2019-16148 1 Sakailms 1 Sakai 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Sakai through 12.6 allows XSS via a chat user name.
CVE-2019-16147 1 Liferay 1 Liferay Portal 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
CVE-2019-16146 1 Getgophish 1 Gophish 2026-06-17 3.5 LOW 4.8 MEDIUM
Gophish through 0.8.0 allows XSS via a username.
CVE-2019-16145 1 Padrinorb 1 Padrino-contrib 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The breadcrumbs contributed module through 0.2.0 for Padrino Framework allows XSS via a caption.
CVE-2019-16130 1 Hgw168cc 1 Yii-cms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html.
CVE-2019-16126 1 Getgrav 1 Grav Cms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
CVE-2019-16118 1 10web 1 Photo Gallery 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.