Vulnerabilities (CVE)

Filtered by CWE-79
Total 47282 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-13138 1 Qodeinteractive 1 Bridge 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
DOM based Cross-site scripting (XSS) vulnerability in the Bridge theme before 11.2 for WordPress allows remote attackers to inject arbitrary JavaScript.
CVE-2017-13073 1 Qnap 1 Photo Station 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.
CVE-2017-13072 1 Qnap 1 Qts 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and their earlier versions could allow remote attackers to inject Javascript code.
CVE-2017-12984 1 Phpmywind 1 Phpmywind 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.
CVE-2017-12980 1 Dokuwiki 1 Dokuwiki 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
DokuWiki through 2017-02-19c has stored XSS when rendering a malicious RSS or Atom feed, in /inc/parser/xhtml.php. An attacker can create or edit a wiki that uses RSS or Atom data from an attacker-controlled server to trigger JavaScript execution. The JavaScript can be in an author field, as demonstrated by the dc:creator element.
CVE-2017-12979 1 Dokuwiki 1 Dokuwiki 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
DokuWiki through 2017-02-19c has stored XSS when rendering a malicious language name in a code element, in /inc/parser/xhtml.php. An attacker can create or edit a wiki with this element to trigger JavaScript execution.
CVE-2017-12978 1 Cacti 1 Cacti 2026-06-17 3.5 LOW 5.4 MEDIUM
lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.
CVE-2017-12971 1 Apache2triad 1 Apache2triad 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the account parameter to phpsftpd/users.php.
CVE-2017-12948 1 Pressforward 1 Pressforward 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Core\Admin\PFTemplater.php in the PressForward plugin 4.3.0 and earlier for WordPress has XSS in the PATH_INFO to wp-admin/admin.php, related to PHP_SELF.
CVE-2017-12927 1 Cacti 1 Cacti 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.
CVE-2017-12907 1 Nexusphp Project 1 Nexusphp 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the url path to usersearch.php.
CVE-2017-12906 1 Nexusphp Project 1 Nexusphp 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in NexusPHP allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) cheaters.php or (2) confirm_resend.php.
CVE-2017-12885 1 Open-xchange 1 Open-xchange Appsuite 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
OX Software GmbH App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
CVE-2017-12882 1 Spring Batch Admin Project 1 Spring Batch Admin 2026-06-17 3.5 LOW 5.4 MEDIUM
Stored Cross-site scripting (XSS) vulnerability in Spring Batch Admin before 1.3.0 allows remote authenticated users to inject arbitrary JavaScript or HTML via the file upload functionality.
CVE-2017-12879 1 Paessler 1 Prtg Network Monitor 2026-06-17 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS-STORED) vulnerability in the DEVICES OR SENSORS functionality in Paessler PRTG Network Monitor before 17.3.33.2654 allows authenticated remote attackers to inject arbitrary web script or HTML.
CVE-2017-12856 1 C.p.sub Project 1 C.p.sub 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in C.P.Sub 5.2 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to index.php.
CVE-2017-12844 1 Icewarp 1 Mail Server 2026-06-17 3.5 LOW 4.8 MEDIUM
Cross-site scripting (XSS) vulnerability in the admin panel in IceWarp Mail Server 10.4.4 allows remote authenticated domain administrators to inject arbitrary web script or HTML via a crafted user name.
CVE-2017-12813 1 Stivasoft 1 Phpjabbers File Sharing Script 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
PHPJabbers File Sharing Script 1.0 has stored XSS in the comments section.
CVE-2017-12812 1 Stivasoft 1 Phpjabbers Night Club Booking Software 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
PHPJabbers Night Club Booking Software has stored XSS in the name parameter in the reservations tab.
CVE-2017-12811 1 Stivasoft 1 Phpjabbers Star Rating Script 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
PHPJabbers Star Rating Script 4.0 has stored XSS via a rating item.