Vulnerabilities (CVE)

Filtered by CWE-79
Total 47280 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-11179 1 Finecms Project 1 Finecms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
FineCMS through 2017-07-11 has stored XSS in route=admin when modifying user information, and in route=register when registering a user account.
CVE-2017-11175 1 Siemens 1 Fin Stack 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
In J2 Innovations FIN Stack 4.0, the authentication webform is vulnerable to reflected XSS via the query string to /login.
CVE-2017-11163 1 Cacti 1 Cacti 2026-06-17 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.
CVE-2017-11128 1 Boltcms 1 Bolt 2026-06-17 3.5 LOW 5.4 MEDIUM
Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.
CVE-2017-11127 1 Boltcms 1 Bolt 2026-06-17 3.5 LOW 5.4 MEDIUM
Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.
CVE-2017-11107 2 Debian, Phpldapadmin Project 2 Debian Linux, Phpldapadmin 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.
CVE-2017-10991 1 Wp-statistics 1 Wp Statistics 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_referrers_page page.
CVE-2017-10975 1 Lutim Project 1 Lutim 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Lutim before 0.8 might allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in an upload notification and in the myfiles component, if the attacker can convince the victim to proceed with an upload despite the appearance of an XSS payload in the filename.
CVE-2017-10970 1 Cacti 1 Cacti 2026-06-17 4.3 MEDIUM 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php.
CVE-2017-10967 1 Finecms Project 1 Finecms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
In FineCMS before 2017-07-06, application\core\controller\config.php allows XSS in the (1) key_name, (2) key_value, and (3) meaning parameters.
CVE-2017-10962 1 Vanderbilt 1 Redcap 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
REDCap before 7.5.1 has XSS via the query string.
CVE-2017-10896 1 Buffalo 4 Bbr-4hg, Bbr-4hg Firmware, Bbr-4mg and 1 more 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Buffalo BBR-4HG and and BBR-4MG broadband routers with firmware 1.00 to 1.48 and 2.00 to 2.07 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-10886 1 Cs-cart 2 Cs-cart, Cs-cart Multivendor 2026-06-17 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-10840 1 Webcalendar Project 1 Webcalendar 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in WebCalendar 1.2.7 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-10838 1 Seopanel 1 Seo Panel 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in SEO Panel prior to version 3.11.0 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-10837 1 Backup-guard 1 Backup Guard 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in BackupGuard prior to version 1.1.47 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-10801 1 Phpsocial 1 Phpsocial 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
phpSocial (formerly phpDolphin) before 3.0.1 has XSS in the PATH_INFO to the search/tag/ URI.
CVE-2017-10798 1 Objectplanet 1 Opinio 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
In ObjectPlanet Opinio before 7.6.4, there is XSS.
CVE-2017-10795 1 Intelliants 1 Subrion 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or HTML via the body to blog/add/, a different vulnerability than CVE-2017-6069.
CVE-2017-10711 1 Simplerisk 1 Simplerisk 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
In SimpleRisk 20170614-001, a CSRF attack on reset.php (aka the Send Password Reset Email form) can insert XSS sequences via the user parameter.