Vulnerabilities (CVE)

Filtered by CWE-79
Total 47284 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-14744 1 Baidu 1 Ueditor 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element.
CVE-2017-14740 1 Genixcms 1 Genixcms 2026-06-17 3.5 LOW 4.8 MEDIUM
Cross-site scripting (XSS) vulnerability in GeniXCMS 1.1.0 allows remote authenticated users to inject arbitrary web script or HTML via the Menu ID when adding a menu.
CVE-2017-14735 1 Antisamy Project 1 Antisamy 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of : to construct a javascript: URL.
CVE-2017-14726 1 Wordpress 1 Wordpress 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.
CVE-2017-14724 1 Wordpress 1 Wordpress 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.
CVE-2017-14721 1 Wordpress 1 Wordpress 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name.
CVE-2017-14720 1 Wordpress 1 Wordpress 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.
CVE-2017-14718 1 Wordpress 1 Wordpress 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL.
CVE-2017-14717 1 Telaxius 1 Epesi 2026-06-17 3.5 LOW 5.4 MEDIUM
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.
CVE-2017-14716 1 Telaxius 1 Epesi 2026-06-17 3.5 LOW 5.4 MEDIUM
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title parameter.
CVE-2017-14715 1 Telaxius 1 Epesi 2026-06-17 3.5 LOW 5.4 MEDIUM
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts Title parameter.
CVE-2017-14714 1 Telaxius 1 Epesi 2026-06-17 3.5 LOW 5.4 MEDIUM
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Subject parameter.
CVE-2017-14713 1 Telaxius 1 Epesi 2026-06-17 3.5 LOW 5.4 MEDIUM
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Description parameter.
CVE-2017-14712 1 Telaxius 1 Epesi 2026-06-17 3.5 LOW 5.4 MEDIUM
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.
CVE-2017-14651 1 Wso2 17 Api Manager, App Manager, Application Server and 14 more 2026-06-17 3.5 LOW 4.8 MEDIUM
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.
CVE-2017-14622 1 2kblater 1 2kb Amazon Affiliates Store 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the 2kb Amazon Affiliates Store plugin before 2.1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter or (2) kbAction parameter in the kbAmz page to wp-admin/admin.php.
CVE-2017-14621 1 Suse 1 Portus 2026-06-17 3.5 LOW 5.4 MEDIUM
Portus 2.2.0 has XSS via the Team field, related to typeahead.
CVE-2017-14620 1 Smartertools 1 Smarterstats 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Stored Cross Site Scripting.
CVE-2017-14619 1 Phpmyfaq 1 Phpmyfaq 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the "Title of your FAQ" field in the Configuration Module.
CVE-2017-14618 1 Phpmyfaq 1 Phpmyfaq 2026-06-17 3.5 LOW 4.8 MEDIUM
Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the Questions field in an "Add New FAQ" action.