Vulnerabilities (CVE)

Filtered by CWE-79
Total 47280 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-10245 1 Doxygen 1 Doxygen 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection.
CVE-2016-10216 1 Sivann 1 It Items Database 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in IT ITems DataBase (ITDB) through 1.23. The vulnerability exists due to insufficient filtration of user-supplied data in the "value" HTTP POST parameter passed to the "itdb-1.23/js/DataTables-1.8.2/examples/examples_support/editable_ajax.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CVE-2016-10215 1 Fastspot 1 Bigtree-form-builder 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Fastspot BigTree bigtree-form-builder before 1.2. The vulnerability exists due to insufficient filtration of user-supplied data in multiple HTTP POST parameters passed to a "site/index.php/../../extensions/com.fastspot.form-builder/ajax/redraw-field.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CVE-2016-10203 1 Zoneminder 1 Zoneminder 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the name when creating a new monitor.
CVE-2016-10202 1 Zoneminder 1 Zoneminder 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the path info to index.php.
CVE-2016-10201 1 Zoneminder 1 Zoneminder 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the format parameter in a download log request to index.php.
CVE-2016-10112 1 Woocommerce 1 Woocommerce 2026-06-17 3.5 LOW 4.8 MEDIUM
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.6.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML by providing crafted tax-rate table values in CSV format.
CVE-2016-10083 1 Piwigo 1 Piwigo 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in a certain error case.
CVE-2016-10006 1 Antisamy Project 1 Antisamy 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.
CVE-2016-1000307 1 Clip-bucket 1 Clipbucket 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Multiple Cross Site Scripting (XSS) Vulnerabilities in ClipBucket v2.8.1 and probably prior allow Remote Attackers to inject arbitrary web script or HTML via (1) profile_desc, about_me, schools, occupation, companies, hobbies, fav_movies, fav_music, fav_books parameters to ProfileSettings page; (2) note parameter to PersonalNotes Section; (3) closed_msg, description, allowed_types parameters to WebsiteConfigurations Section. NOTE: the collection_description vector is already covered by CVE-2015-4673.
CVE-2016-1000237 1 Apostrophecms 1 Sanitize-html 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
sanitize-html before 1.4.3 has XSS.
CVE-2016-1000229 2 Redhat, Smartbear 3 Jboss Fuse, Openshift, Swagger-ui 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
swagger-ui has XSS in key names
CVE-2016-1000220 1 Elastic 1 Kibana 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.
CVE-2016-1000155 1 Wpsolr 1 Wpsolr-search-engine 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin wpsolr-search-engine v7.6
CVE-2016-1000154 1 Browserweb 1 Whizz 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin whizz v1.0.7
CVE-2016-1000153 1 Tidio-gallery Project 1 Tidio-gallery 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin tidio-gallery v1.1
CVE-2016-1000152 1 Tidio-form Project 1 Tidio-form 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin tidio-form v1.0
CVE-2016-1000151 1 Tera-charts Project 1 Tera-charts 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin tera-charts v1.0
CVE-2016-1000150 1 Oxil 1 Simplified-content 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin simplified-content v1.0.0
CVE-2016-1000149 1 Simpel-reserveren Project 1 Simpel-reserveren 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin simpel-reserveren v3.5.2