Vulnerabilities (CVE)

Filtered by CWE-79
Total 47288 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-17694 1 Techno - Portfolio Management Panel Project 1 Techno - Portfolio Management Panel 2026-06-17 3.5 LOW 5.4 MEDIUM
Techno - Portfolio Management Panel through 2017-11-16 allows XSS via the panel/search.php s parameter.
CVE-2017-17569 1 Scubez 1 Posty Readymade Classifieds 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Scubez Posty Readymade Classifieds has XSS via the admin/user_activate_submit.php ID parameter.
CVE-2017-17541 1 Fortinet 2 Fortianalyzer Firmware, Fortimanager Firmware 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.
CVE-2017-17478 1 Pega 1 Pega Platform 2026-06-17 3.5 LOW 4.8 MEDIUM
An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. A user with developer credentials can insert malicious code (up to 64 characters) into a text field in Designer Studio, after establishing context. Designer Studio is the developer workbench for Pega Platform. That XSS payload will execute when other developers visit the affected pages.
CVE-2017-17477 1 Pexip 1 Pexip Infinity 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views.
CVE-2017-17454 1 Mahara 1 Mahara 2026-06-17 3.5 LOW 5.4 MEDIUM
Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerability when a user enters invalid UTF-8 characters. These are now going to be discarded in Mahara along with NULL characters and invalid Unicode characters. Mahara will also avoid direct $_GET and $_POST usage where possible, and instead use param_exists() and the correct param_*() function to fetch the expected value.
CVE-2017-17451 1 Wpmailster 1 Wp Mailster 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The WP Mailster plugin before 1.5.5 for WordPress has XSS in the unsubscribe handler via the mes parameter to view/subscription/unsubscribe2.php.
CVE-2017-17442 1 Blackberry 1 Unified Endpoint Manager 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
In BlackBerry UEM Management Console version 12.7.1 and earlier, a reflected cross-site scripting vulnerability that could allow an attacker to execute script commands in the context of the affected UEM Management Console account by crafting a malicious link and then persuading a user with legitimate access to the Management Console to click on the malicious link.
CVE-2017-17431 1 Genixcms 1 Genixcms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
GeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter. NOTE: this might overlap CVE-2017-14761, CVE-2017-14762, or CVE-2017-14765.
CVE-2017-17383 1 Jenkins 1 Jenkins 2026-06-17 3.5 LOW 4.7 MEDIUM
Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
CVE-2017-17096 1 Content Cards Project 1 Content Cards 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the Content Cards plugin before 0.9.7 for WordPress allows remote attackers to inject arbitrary JavaScript via crafted OpenGraph data.
CVE-2017-17094 2 Debian, Wordpress 2 Debian Linux, Wordpress 2026-06-17 3.5 LOW 5.4 MEDIUM
wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.
CVE-2017-17093 2 Debian, Wordpress 2 Debian Linux, Wordpress 2026-06-17 3.5 LOW 5.4 MEDIUM
wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.
CVE-2017-17092 2 Debian, Wordpress 2 Debian Linux, Wordpress 2026-06-17 3.5 LOW 5.4 MEDIUM
wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.
CVE-2017-17089 1 Webmin 1 Webmin 2026-06-17 3.5 LOW 4.8 MEDIUM
custom/run.cgi in Webmin before 1.870 allows remote authenticated administrators to conduct XSS attacks via the description field in the custom command functionality.
CVE-2017-17062 1 Open-xchange 1 Open-xchange Appsuite 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev19 allows remote authenticated users to save arbitrary user attributes by leveraging improper privilege management.
CVE-2017-17061 1 Open-xchange 1 Open-xchange Appsuite 2026-06-17 3.5 LOW 5.4 MEDIUM
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
CVE-2017-17059 1 Amtythumb Project 1 Amtythumb 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
XSS exists in the amtyThumb amty-thumb-recent-post (aka amtyThumb posts or wp-thumb-post) plugin 8.1.3 for WordPress via the query string to amtyThumbPostsAdminPg.php.
CVE-2017-17057 1 Zkteco 1 Zktime Web 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
There is a reflected XSS vulnerability in ZKTime Web 2.0.1.12280. The vulnerability exists due to insufficient filtration of user-supplied data in the 'Range' field of the 'Department' module in a Personnel Advanced Query. A remote attacker can execute arbitrary HTML and script code in the browser in the context of the vulnerable application.
CVE-2017-17043 1 Zitec 1 Emag Marketplace Connector 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Emag Marketplace Connector plugin 1.0.0 for WordPress has reflected XSS because the parameter "post" to /wp-content/plugins/emag-marketplace-connector/templates/order/awb-meta-box.php is not filtered correctly.