Vulnerabilities (CVE)

Filtered by CWE-79
Total 47280 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1000240 1 Open-emr 1 Openemr 2026-06-17 3.5 LOW 5.4 MEDIUM
The application OpenEMR is affected by multiple reflected & stored Cross-Site Scripting (XSS) vulnerabilities affecting version 5.0.0 and prior versions. These vulnerabilities could allow remote authenticated attackers to inject arbitrary web script or HTML.
CVE-2017-1000239 1 Invoiceplane 1 Invoiceplane 2026-06-17 3.5 LOW 5.4 MEDIUM
InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious client side script which will be executed in the browser of users if they visit the manipulated site.
CVE-2017-1000236 1 Scilico 1 I\, Librarian 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
I, Librarian version <=4.6 & 4.7 is vulnerable to Reflected Cross-Site Scripting in the temp.php resulting in an attacker being able to inject malicious client side scripting which will be executed in the browser of users if they visit the manipulated site.
CVE-2017-1000227 1 Parallelus 1 Salutation 2026-06-17 3.5 LOW 5.4 MEDIUM
Stored XSS in Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 could allow logged-in users to do almost anything an admin can
CVE-2017-1000225 1 Relevanssi 1 Relevanssi 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in Relevanssi Premium version 1.14.8 when using relevanssi_didyoumean() could allow unauthenticated attacker to do almost anything an admin can
CVE-2017-1000223 1 Modx 1 Modx Revolution 2026-06-17 3.5 LOW 5.4 MEDIUM
A stored web content injection vulnerability (WCI, a.k.a XSS) is present in MODX Revolution CMS version 2.5.6 and earlier. An authenticated user with permissions to edit users can save malicious JavaScript as a User Group name and potentially take control over victims' accounts. This can lead to an escalation of privileges providing complete administrative control over the CMS.
CVE-2017-1000213 1 Wbce 1 Wbce Cms 2026-06-17 3.5 LOW 4.8 MEDIUM
WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search
CVE-2017-1000193 1 Octobercms 1 October 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.
CVE-2017-1000188 1 Ejs 1 Ejs 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code injection
CVE-2017-1000164 1 Tine20 1 Tine 2.0 2026-06-17 3.5 LOW 5.4 MEDIUM
Tine 2.0 version 2017.02.4 is vulnerable to XSS in the Addressbook resulting code execution and privilege escalation
CVE-2017-1000160 1 Expressionengine 1 Expressionengine 2026-06-17 3.5 LOW 5.4 MEDIUM
EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection
CVE-2017-1000149 1 Mahara 1 Mahara 2026-06-17 3.5 LOW 5.4 MEDIUM
Mahara 1.10 before 1.10.9 and 15.04 before 15.04.6 and 15.10 before 15.10.2 are vulnerable to XSS due to window.opener (target="_blank" and window.open())
CVE-2017-1000146 1 Mahara 1 Mahara 2026-06-17 3.5 LOW 5.4 MEDIUM
Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script that updates the Add/remove watchlist link on artefact detail pages.
CVE-2017-1000144 1 Mahara 1 Mahara 2026-06-17 3.5 LOW 4.8 MEDIUM
Mahara 1.9 before 1.9.6 and 1.10 before 1.10.4 and 15.04 before 15.04.1 are vulnerable to a site admin or institution admin being able to place HTML and Javascript into an institution display name, which will be displayed to other users unescaped on some Mahara system pages.
CVE-2017-1000140 1 Mahara 1 Mahara 2026-06-17 3.5 LOW 5.4 MEDIUM
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .xml file that can have its code executed when user tries to download the file.
CVE-2017-1000138 1 Mahara 1 Mahara 2026-06-17 3.5 LOW 5.4 MEDIUM
Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when dragging/dropping files into a collection if the file has Javascript code in its title.
CVE-2017-1000137 1 Mahara 1 Mahara 2026-06-17 3.5 LOW 5.4 MEDIUM
Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when adding a text block to a page via the keyboard (rather than drag and drop).
CVE-2017-1000132 1 Mahara 1 Mahara 2026-06-17 3.5 LOW 4.8 MEDIUM
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .swf files that can have its code executed when a user tries to download the file.
CVE-2017-1000109 1 Jenkins 1 Owasp Dependency-check 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to this plugin could insert arbitrary HTML into this view.
CVE-2017-1000103 1 Jenkins 1 Dry 2026-06-17 3.5 LOW 5.4 MEDIUM
The custom Details view of the Static Analysis Utilities based DRY Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to this plugin could insert arbitrary HTML into this view.