Vulnerabilities (CVE)

Filtered by CWE-79
Total 47303 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-11627 2 Redhat, Sinatrarb 2 Cloudforms, Sinatra 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
CVE-2018-11588 1 Centreon 2 Centreon, Centreon Web 2026-06-17 3.5 LOW 5.4 MEDIUM
Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or command description, resulting in stored XSS. This is related to www/include/core/menu/menu.php and www/include/configuration/configObject/command/formArguments.php.
CVE-2018-11583 1 Seacms 1 Seacms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter.
CVE-2018-11581 1 Brother 4 Hl-l2340d, Hl-l2340d Firmware, Hl-l2380dw and 1 more 2026-06-17 3.5 LOW 4.8 MEDIUM
Cross-site scripting (XSS) vulnerability on Brother HL series printers allows remote attackers to inject arbitrary web script or HTML via the url parameter to etc/loginerror.html.
CVE-2018-11580 1 Multidots 1 Mass Pages\/posts Creator 2026-06-17 3.5 LOW 5.4 MEDIUM
An issue was discovered in mass-pages-posts-creator.php in the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2 for WordPress. Any logged in user can launch Mass Pages/Posts creation with custom content. There is no nonce or user capability check, so anyone can launch a DoS attack against a site and create hundreds of thousands of posts with custom content.
CVE-2018-11572 1 Clippercms 1 Clippercms 2026-06-17 3.5 LOW 5.4 MEDIUM
ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.
CVE-2018-11568 1 Cactusthemes 1 Gameplan-event And Gym Fitness 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS is possible in the GamePlan theme through 1.5.13.2 for WordPress because of insufficient input sanitization, as demonstrated by the s parameter. In some (but not all) cases, the '<' and '>' characters have &lt; and &gt; representations.
CVE-2018-11564 1 Pagekit 1 Pagekit 2026-06-17 3.5 LOW 4.8 MEDIUM
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG format. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to "/storage/poc.svg" that will point to http://localhost/pagekit/storage/poc.svg. When a user comes along to click that link, it will trigger a XSS attack.
CVE-2018-11559 1 Domainmod 1 Domainmod 2026-06-17 3.5 LOW 5.4 MEDIUM
DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_last_name parameter.
CVE-2018-11558 1 Domainmod 1 Domainmod 2026-06-17 3.5 LOW 5.4 MEDIUM
DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter.
CVE-2018-11557 1 Yiban 1 Easy Class Education Platform 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
YIBAN Easy class education platform 2.0 has XSS via the articlelist.php k parameter.
CVE-2018-11553 1 Sgin 1 Xiangyun Platform 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php.
CVE-2018-11552 1 Nch 1 Axon Pbx 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
There is a reflected XSS vulnerability in AXON PBX 2.02 via the "AXON->Auto-Dialer->Agents->Name" field. The vulnerability exists due to insufficient filtration of user-supplied data. A remote attacker can execute arbitrary HTML and script code in a browser in the context of the vulnerable application.
CVE-2018-11549 1 Wuzhicms 1 Wuzhicms 2026-06-17 3.5 LOW 5.4 MEDIUM
An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq_10]= substring.
CVE-2018-11532 1 Changuondyu Advanced Statistics Project 1 Changuondyu Advanced Statistics 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field.
CVE-2018-11522 1 Yosoro Project 1 Yosoro 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Yosoro 1.0.4 has stored XSS.
CVE-2018-11512 1 Creatiwity 1 Witycms 2026-06-17 3.5 LOW 4.8 MEDIUM
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to admin/settings/general.
CVE-2018-11501 1 Website Seller Script Project 1 Website Seller Script 2026-06-17 6.0 MEDIUM 8.8 HIGH
PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS.
CVE-2018-11487 1 Phpmywind 1 Phpmywind 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
PHPMyWind 5.5 has XSS via the cid parameter to newsshow.php, or the query string to news.php or about.php.
CVE-2018-11486 1 Multidots 1 Advance Search For Woocommerce 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in the MULTIDOTS Advance Search for WooCommerce plugin 1.0.9 and earlier for WordPress. This plugin is vulnerable to a stored Cross-site scripting (XSS) vulnerability. A non-authenticated user can save the plugin settings and inject malicious JavaScript code in the Custom CSS textarea field, which will be loaded on every site page.