Total
47284 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2017-15867 | 1 User-login-history Project | 1 User-login-history | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Multiple cross-site scripting (XSS) vulnerabilities in the user-login-history plugin through 1.5.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) date_from, (2) date_to, (3) user_id, (4) username, (5) country_name, (6) browser, (7) operating_system, or (8) ip_address parameter to admin/partials/listing/listing.php. | |||||
| CVE-2017-15863 | 1 Wp No External Links Project | 1 Wp No External Links | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross Site Scripting (XSS) exists in the wp-noexternallinks plugin before 3.5.19 for WordPress via the date1 or date2 parameter to wp-admin/options-general.php. | |||||
| CVE-2017-15812 | 1 Easy-appointments | 1 Easy Appointments | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| The Easy Appointments plugin before 1.12.0 for WordPress has XSS via a Settings values in the admin panel. | |||||
| CVE-2017-15811 | 1 Pootlepress | 1 Pootle Button | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| The Pootle Button plugin before 1.2.0 for WordPress has XSS via the assets_url parameter in assets/dialog.php, exploitable via wp-admin/admin-ajax.php. | |||||
| CVE-2017-15810 | 1 Popcash | 1 Popcash.net Code Integration Tool | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| The PopCash.Net Code Integration Tool plugin before 1.1 for WordPress has XSS via the tab parameter to wp-admin/admin.php. | |||||
| CVE-2017-15809 | 1 Phpmyfaq | 1 Phpmyfaq | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| In phpMyFaq before 2.9.9, there is XSS in admin/tags.main.php via a crafted tag. | |||||
| CVE-2017-15736 | 1 Spip | 1 Spip | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability (stored) in SPIP before 3.1.7 allows remote attackers to inject arbitrary web script or HTML via a crafted string, as demonstrated by a PGP field, related to prive/objets/contenu/auteur.html and ecrire/inc/texte_mini.php. | |||||
| CVE-2017-15728 | 1 Phpmyfaq | 1 Phpmyfaq | 2026-06-17 | 3.5 LOW | 4.8 MEDIUM |
| In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via metaDescription or metaKeywords. | |||||
| CVE-2017-15727 | 1 Phpmyfaq | 1 Phpmyfaq | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment. | |||||
| CVE-2017-15719 | 1 Wicket-jquery-ui Project | 1 Wicket-jquery-ui | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor. | |||||
| CVE-2017-15717 | 1 Apache | 2 Sling Xss Protection Api, Sling Xss Protection Api Compat | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affected versions are Apache Sling XSS Protection API 1.0.4 to 1.0.18, Apache Sling XSS Protection API Compat 1.1.0 and Apache Sling XSS Protection API 2.0.0. | |||||
| CVE-2017-15687 | 1 Logitech | 1 Media Server | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI. | |||||
| CVE-2017-15686 | 1 Craftercms | 1 Crafter Cms | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Crafter CMS Crafter Studio 3.0.1 is affected by: Cross Site Scripting (XSS), which allows remote attackers to steal users’ cookies. | |||||
| CVE-2017-15648 | 1 Phpsugar | 1 Php Melody | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| In PHPSUGAR PHP Melody before 2.7.3, page_manager.php has XSS via the page_title parameter. | |||||
| CVE-2017-15646 | 1 Webmin | 1 Webmin | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option to download a file from a remote server. After setting up a malicious server, one can wait for a file download request and then send an XSS payload that will lead to Remote Code Execution, as demonstrated by an OS command in the value attribute of a name='cmd' input element. | |||||
| CVE-2017-15640 | 1 Phpipam | 1 Phpipam | 2026-06-17 | 3.5 LOW | 5.4 MEDIUM |
| app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter. | |||||
| CVE-2017-15612 | 1 Mistune Project | 1 Mistune | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions. | |||||
| CVE-2017-15574 | 2 Debian, Redmine | 2 Debian Linux, Redmine | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment. | |||||
| CVE-2017-15573 | 2 Debian, Redmine | 2 Debian Linux, Redmine | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content. | |||||
| CVE-2017-15571 | 2 Debian, Redmine | 2 Debian Linux, Redmine | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data. | |||||
