Vulnerabilities (CVE)

Filtered by CWE-79
Total 47280 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1000102 1 Jenkins 1 Static Analysis Utilities 2026-06-17 3.5 LOW 5.4 MEDIUM
The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to these plugins, for example the console output which is parsed to extract build warnings (Warnings Plugin), could insert arbitrary HTML into this view.
CVE-2017-1000088 1 Jenkins 1 Sidebar Link 2026-06-17 3.5 LOW 5.4 MEDIUM
The Sidebar Link plugin allows users able to configure jobs, views, and agents to add entries to the sidebar of these objects. There was no input validation, which meant users were able to use javascript: schemes for these links.
CVE-2017-1000078 1 Onosproject 1 Onos 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration
CVE-2017-1000065 1 Openmediavault 1 Openmediavault 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows attackers to inject arbitrary web scripts and execute malicious scripts within an authenticated client's browser.
CVE-2017-1000063 1 Kitto Project 1 Kitto 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
kittoframework kitto version 0.5.1 is vulnerable to an XSS in the 404 page resulting in information disclosure
CVE-2017-1000059 1 Livehelperchat 1 Live Helper Chat 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Live Helper Chat version 2.06v and older is vulnerable to Cross-Site Scripting in the HTTP Header handling resulting in the execution of any user provided Javascript code in the session of other users.
CVE-2017-1000058 1 Chevereto 1 Chevereto 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data parser.
CVE-2017-1000054 1 Rocketchat 1 Rocket.chat 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages.
CVE-2017-1000051 1 Xwiki 1 Cryptpad 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in pad export in XWiki labs CryptPad before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the pad content
CVE-2017-1000043 1 Mapbox 1 Mapbox.js 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Mapbox.js versions 1.x prior to 1.6.6 and 2.x prior to 2.2.4 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON name and map share control
CVE-2017-1000042 1 Mapbox Project 1 Mapbox 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Mapbox.js versions 1.x prior to 1.6.5 and 2.x prior to 2.1.7 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON Name.
CVE-2017-1000038 1 Relevanssi 1 Relevanssi 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the affected site
CVE-2017-1000035 1 Tt-rss 1 Tiny Tiny Rss 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Tiny Tiny RSS before 829d478f is vulnerable to XSS window.opener attack
CVE-2017-1000033 1 Vospari Forms Project 1 Vospari Forms 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Wordpress Plugin Vospari Forms version < 1.4 is vulnerable to a reflected cross site scripting in the form submission resulting in javascript code execution in the context on the current user.
CVE-2017-1000032 1 Cacti 1 Cacti 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.
CVE-2017-1000023 1 Logicaldoc 1 Logicaldoc 2026-06-17 3.5 LOW 5.4 MEDIUM
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document.
CVE-2017-1000015 1 Phpmyadmin 1 Phpmyadmin 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters
CVE-2017-1000012 1 Mysqldumper 1 Mysqldumper 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
MySQL Dumper version 1.24 is vulnerable to stored XSS when displaying the data in the database to the user
CVE-2017-1000011 1 Mywebsql 1 Mywebsql 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
MyWebSQL version 3.6 is vulnerable to stored XSS in the database manager component resulting in account takeover or stealing of information
CVE-2017-1000006 1 Plotly 1 Plotly.js 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Plotly, Inc. plotly.js versions prior to 1.16.0 are vulnerable to an XSS issue.