Total
47280 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2016-10245 | 1 Doxygen | 1 Doxygen | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection. | |||||
| CVE-2016-10216 | 1 Sivann | 1 It Items Database | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in IT ITems DataBase (ITDB) through 1.23. The vulnerability exists due to insufficient filtration of user-supplied data in the "value" HTTP POST parameter passed to the "itdb-1.23/js/DataTables-1.8.2/examples/examples_support/editable_ajax.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | |||||
| CVE-2016-10215 | 1 Fastspot | 1 Bigtree-form-builder | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| An issue was discovered in Fastspot BigTree bigtree-form-builder before 1.2. The vulnerability exists due to insufficient filtration of user-supplied data in multiple HTTP POST parameters passed to a "site/index.php/../../extensions/com.fastspot.form-builder/ajax/redraw-field.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | |||||
| CVE-2016-10203 | 1 Zoneminder | 1 Zoneminder | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the name when creating a new monitor. | |||||
| CVE-2016-10202 | 1 Zoneminder | 1 Zoneminder | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the path info to index.php. | |||||
| CVE-2016-10201 | 1 Zoneminder | 1 Zoneminder | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the format parameter in a download log request to index.php. | |||||
| CVE-2016-10112 | 1 Woocommerce | 1 Woocommerce | 2026-06-17 | 3.5 LOW | 4.8 MEDIUM |
| Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format. | |||||
| CVE-2016-10083 | 1 Piwigo | 1 Piwigo | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in a certain error case. | |||||
| CVE-2016-10006 | 1 Antisamy Project | 1 Antisamy | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS. | |||||
| CVE-2016-1000307 | 1 Clip-bucket | 1 Clipbucket | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Multiple Cross Site Scripting (XSS) Vulnerabilities in ClipBucket v2.8.1 and probably prior allow Remote Attackers to inject arbitrary web script or HTML via (1) profile_desc, about_me, schools, occupation, companies, hobbies, fav_movies, fav_music, fav_books parameters to ProfileSettings page; (2) note parameter to PersonalNotes Section; (3) closed_msg, description, allowed_types parameters to WebsiteConfigurations Section. NOTE: the collection_description vector is already covered by CVE-2015-4673. | |||||
| CVE-2016-1000237 | 1 Apostrophecms | 1 Sanitize-html | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| sanitize-html before 1.4.3 has XSS. | |||||
| CVE-2016-1000229 | 2 Redhat, Smartbear | 3 Jboss Fuse, Openshift, Swagger-ui | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| swagger-ui has XSS in key names | |||||
| CVE-2016-1000220 | 1 Elastic | 1 Kibana | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers. | |||||
| CVE-2016-1000155 | 1 Wpsolr | 1 Wpsolr-search-engine | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Reflected XSS in wordpress plugin wpsolr-search-engine v7.6 | |||||
| CVE-2016-1000154 | 1 Browserweb | 1 Whizz | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Reflected XSS in wordpress plugin whizz v1.0.7 | |||||
| CVE-2016-1000153 | 1 Tidio-gallery Project | 1 Tidio-gallery | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Reflected XSS in wordpress plugin tidio-gallery v1.1 | |||||
| CVE-2016-1000152 | 1 Tidio-form Project | 1 Tidio-form | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Reflected XSS in wordpress plugin tidio-form v1.0 | |||||
| CVE-2016-1000151 | 1 Tera-charts Project | 1 Tera-charts | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Reflected XSS in wordpress plugin tera-charts v1.0 | |||||
| CVE-2016-1000150 | 1 Oxil | 1 Simplified-content | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Reflected XSS in wordpress plugin simplified-content v1.0.0 | |||||
| CVE-2016-1000149 | 1 Simpel-reserveren Project | 1 Simpel-reserveren | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Reflected XSS in wordpress plugin simpel-reserveren v3.5.2 | |||||
