Vulnerabilities (CVE)

Filtered by CWE-79
Total 47284 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-14983 1 Eyesofnetwork 1 Eyesofnetwork 2026-06-17 3.5 LOW 4.8 MEDIUM
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to inject arbitrary web script or HTML via the object parameter to module/admin_conf/index.php.
CVE-2017-14981 1 Atutor 1 Atutor 2026-06-17 3.5 LOW 5.4 MEDIUM
Cross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The vulnerability exists due to insufficient filtration of data (url in /mods/_standard/rss_feeds/edit_feed.php). An attacker could inject arbitrary HTML and script code into a browser in the context of the vulnerable website.
CVE-2017-14973 1 Identicard 1 Two-reader Controller Configuration Manager 2026-06-17 3.5 LOW 5.4 MEDIUM
IDenticard Two-Reader Controller Configuration Manager 1.18.8 (396) is vulnerable to Stored Cross-Site Scripting (XSS) via the notes field in /~user_handler?file=logged_in.shtm (aka the edit user page).
CVE-2017-14957 1 Blogotext Project 1 Blogotext 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Stored XSS vulnerability via a comment in inc/conv.php in BlogoText before 3.7.6 allows an unauthenticated attacker to inject JavaScript. If the victim is an administrator, an attacker can (for example) change global settings or create/delete posts. It is also possible to execute JavaScript against unauthenticated users of the blog.
CVE-2017-14923 1 Tine20 1 Tine 2.0 2026-06-17 3.5 LOW 5.4 MEDIUM
Stored XSS vulnerability via IMG element at "Leadname" of CRM in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mishandled during rendering by the application administrator and other users.
CVE-2017-14922 1 Tine20 1 Tine 2.0 2026-06-17 3.5 LOW 5.4 MEDIUM
Stored XSS vulnerability via IMG element at "History" of Profile, Calendar, Tasks, and CRM in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mishandled during rendering by the application administrator and other users.
CVE-2017-14921 1 Tine20 1 Tine 2.0 2026-06-17 3.5 LOW 5.4 MEDIUM
Stored XSS vulnerability via IMG element at "Filename" of Filemanager in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mishandled during rendering by the application administrator and other users.
CVE-2017-14920 1 Egroupware 1 Egroupware 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript via the User-Agent HTTP header, which is mishandled during rendering by the application administrator.
CVE-2017-14850 1 Orpak 1 Siteomat 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site Scripting due to improper external user-input validation. An attacker with access to the web interface is able to hijack sessions or navigate victims outside of SiteOmat, to a malicious server owned by him.
CVE-2017-14801 1 Netiq 1 Access Manager 2026-06-17 4.3 MEDIUM 4.6 MEDIUM
Reflected XSS in the NetIQ Access Manager before 4.3.3 allowed attackers to reflect back xss into the called page using the url parameter.
CVE-2017-14800 1 Netiq 1 Access Manager 2026-06-17 4.3 MEDIUM 5.4 MEDIUM
A reflected cross site scripting attack in the NetIQ Access Manager before 4.3.3 using the "typecontainerid" parameter of the policy editor could allowed code injection into pages of authenticated users.
CVE-2017-14799 1 Netiq 1 Access Manager 2026-06-17 4.3 MEDIUM 4.6 MEDIUM
A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager before 4.3.3 could be used to inject javascript code into the login page.
CVE-2017-14765 1 Genixcms 1 Genixcms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
In GeniXCMS 1.1.4, gxadmin/index.php has XSS via the Menu ID field in a page=menus request.
CVE-2017-14762 1 Genixcms 1 Genixcms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
In GeniXCMS 1.1.4, /inc/lib/Control/Backend/menus.control.php has XSS via the id parameter.
CVE-2017-14761 1 Genixcms 1 Genixcms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
In GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter.
CVE-2017-14756 1 Opentext 1 Document Sciences Xpression 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Cross-Site Scripting: /xAdmin/html/Deployment (cat_id).
CVE-2017-14755 1 Opentext 1 Document Sciences Xpression 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Cross-Site Scripting: /xAdmin/html/XPressoDoc, parameter: categoryId.
CVE-2017-14753 1 Eyesofnetwork 1 Eyesofnetwork 2026-06-17 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary web script or HTML via the filter parameter to module/module_filters/index.php.
CVE-2017-14752 1 Mahara 1 Mahara 2026-06-17 3.5 LOW 5.4 MEDIUM
Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as their first name, last name, or display name in the profile fields that can cause issues such as escalation of privileges or unknown execution of malicious code when replying to messages in Mahara.
CVE-2017-14751 1 Intensewp 1 Wp Jobs 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The Intense WP "WP Jobs" plugin 1.5 for WordPress has XSS, related to the Job Qualification field.