Vulnerabilities (CVE)

Filtered by CWE-79
Total 47334 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-17587 1 Airties 2 Air 5750, Air 5750 Firmware 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
CVE-2018-17586 1 Wpfastestcache 1 Wp Fastest Cache 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_timeout_pages action.
CVE-2018-17585 1 Wpfastestcache 1 Wp Fastest Cache 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the wpfastestcacheoptions wpFastestCachePreload_number or wpFastestCacheLanguage parameter.
CVE-2018-17583 1 Wpfastestcache 1 Wp Fastest Cache 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pages action.
CVE-2018-17574 1 Ymfe 1 Yapi 2026-06-17 3.5 LOW 5.4 MEDIUM
An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project.
CVE-2018-17572 1 Influxdata 1 Influxdb 2026-06-17 3.5 LOW 4.8 MEDIUM
InfluxDB 0.9.5 has Reflected XSS in the Write Data module.
CVE-2018-17571 1 Vanillaforums 1 Vanilla 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Vanilla before 2.6.1 allows XSS via the email field of a profile.
CVE-2018-17560 1 Teamwire 1 Teamwire 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The admin interface of the Grouptime Teamwire Client 1.5.1 prior to 1.9.0 on-premises messenger server allows stored XSS. All backend versions prior to prod-2018-11-13-15-00-42 are affected.
CVE-2018-17556 1 Modx 1 Modx Revolution 2026-06-17 3.5 LOW 5.4 MEDIUM
MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.
CVE-2018-17537 1 Gitlab 1 Gitlab 2026-06-17 N/A 5.4 MEDIUM
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. blog-viewer has stored XSS during repository browsing, if package.json exists. .
CVE-2018-17536 1 Gitlab 1 Gitlab 2026-06-17 N/A 5.4 MEDIUM
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the merge request page via project import.
CVE-2018-17533 1 Teltonika 6 Rut900, Rut900 Firmware, Rut950 and 3 more 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlogin.cgi due to insufficient user input sanitization.
CVE-2018-17454 1 Gitlab 1 Gitlab 2026-06-17 N/A 5.4 MEDIUM
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the issue details screen.
CVE-2018-17443 1 Dlink 1 Central Wifimanager 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoint is vulnerable to stored XSS.
CVE-2018-17441 1 Dlink 1 Central Wifimanager 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to stored XSS.
CVE-2018-17426 1 Wuzhicms 1 Wuzhicms 2026-06-17 3.5 LOW 5.4 MEDIUM
WUZHI CMS 4.1.0 has stored XSS via the "Extension module" "SMS in station" field under the index.php?m=core URI.
CVE-2018-17425 1 Wuzhicms 1 Wuzhicms 2026-06-17 3.5 LOW 5.4 MEDIUM
WUZHI CMS 4.1.0 has stored XSS via the "Membership Center" "I want to ask" "detailed description" field under the index.php?m=member URI.
CVE-2018-17423 1 E107 1 E107 2026-06-17 3.5 LOW 4.8 MEDIUM
An issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php.
CVE-2018-17421 1 Zrlog 1 Zrlog 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname.
CVE-2018-17413 1 Zzcms 1 Zzcms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
XSS exists in zzcms v8.3 via the /uploadimg_form.php noshuiyin parameter.