Vulnerabilities (CVE)

Filtered by CWE-79
Total 47282 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-12810 1 Stivasoft 1 Phpjabbers Newsletter Script 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
PHPJabbers PHP Newsletter Script 4.2 has stored XSS in lists in the admin panel.
CVE-2017-12798 1 Nexusphp Project 1 Nexusphp 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php.
CVE-2017-12794 1 Djangoproject 1 Django 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for the technical 500 debug page. Given the right circumstances, this allowed a cross-site scripting attack. This vulnerability shouldn't affect most production sites since you shouldn't run with "DEBUG = True" (which makes this page accessible) in your production settings.
CVE-2017-12792 1 Nexusphp Project 1 Nexusphp 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) linkname, (2) url, or (3) title parameter in an add action to linksmanage.php.
CVE-2017-12788 1 Metinfo 1 Metinfo 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in Metinfo 5.3.18 allows remote attackers to inject arbitrary web script or HTML via the (1) class1 parameter or the (2) anyid parameter.
CVE-2017-12777 1 Nexusphp Project 1 Nexusphp 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php.
CVE-2017-12738 1 Siemens 2 Sm-2556, Sm-2556 Firmware 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected devices could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into clicking on a malicious link.
CVE-2017-12680 1 Nexusphp Project 1 Nexusphp 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-Site Scripting (XSS) exists in NexusPHP 1.5 via the type parameter to shoutbox.php.
CVE-2017-12677 1 Identityserver 1 Identityserver3 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
IdentityServer3 2.4.x, 2.5.x, and 2.6.x before 2.6.1 has XSS in an Angular expression on the authorize response page, which might allow remote attackers to obtain sensitive information about the IdentityServer authorization response.
CVE-2017-12655 1 Nexusphp Project 1 Nexusphp 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the query parameter to log.php in a dailylog action.
CVE-2017-12649 1 Liferay 1 Liferay Portal 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted title or summary that is mishandled in the Web Content Display.
CVE-2017-12648 1 Liferay 1 Liferay Portal 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
XSS exists in Liferay Portal before 7.0 CE GA4 via a bookmark URL.
CVE-2017-12647 1 Liferay 1 Liferay Portal 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
XSS exists in Liferay Portal before 7.0 CE GA4 via a Knowledge Base article title.
CVE-2017-12646 1 Liferay 1 Liferay Portal 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
XSS exists in Liferay Portal before 7.0 CE GA4 via a login name, password, or e-mail address.
CVE-2017-12645 1 Liferay 1 Liferay Portal 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
XSS exists in Liferay Portal before 7.0 CE GA4 via an invalid portletId.
CVE-2017-12630 1 Apache 1 Drill 2026-06-17 3.5 LOW 5.4 MEDIUM
In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Query page, malicious user may obtain this information from Profile page afterwards.
CVE-2017-12614 1 Apache 1 Airflow 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is to upgrade to Apache Airflow 1.9.0 or above.
CVE-2017-12591 1 Asus 2 Dsl-n10s, Dsl-n10s Firmware 2026-06-17 3.5 LOW 5.4 MEDIUM
ASUS DSL-N10S V2.1.16_APAC devices have reflected and stored cross site scripting, as demonstrated by the snmpSysName parameter.
CVE-2017-12590 1 Asus 2 Rt-n14uhp, Rt-n14uhp Firmware 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
ASUS RT-N14UHP devices before 3.0.0.4.380.8015 have a reflected XSS vulnerability in the "flag" parameter.
CVE-2017-12583 1 Dokuwiki 1 Dokuwiki 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
DokuWiki through 2017-02-19b has XSS in the at parameter (aka the DATE_AT variable) to doku.php.