Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2019-09-23 CVE-2019-12407 Cross-site Scripting vulnerability in Apache Jspwiki
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the remember parameter on some of the JSPs, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
apache CWE-79
4.3
2019-09-23 CVE-2019-10090 Cross-site Scripting vulnerability in Apache Jspwiki
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the plain editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
apache CWE-79
4.3
2019-09-23 CVE-2019-12404 Cross-site Scripting vulnerability in Apache Jspwiki
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to InfoContent.jsp, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
apache CWE-79
4.3
2019-09-23 CVE-2019-10089 Cross-site Scripting vulnerability in Apache Jspwiki
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
apache CWE-79
4.3
2019-09-23 CVE-2019-10087 Cross-site Scripting vulnerability in Apache Jspwiki
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Page Revision History, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
apache CWE-79
4.3
2019-09-23 CVE-2019-16704 Cross-site Scripting vulnerability in PHPmywind 5.6
admin/infoclass_update.php in PHPMyWind 5.6 has stored XSS.
network
phpmywind CWE-79
3.5
2019-09-23 CVE-2019-16703 Cross-site Scripting vulnerability in PHPmywind 5.6
admin/infolist_add.php in PHPMyWind 5.6 has stored XSS.
network
phpmywind CWE-79
4.3
2019-09-21 CVE-2019-16681 Cross-site Scripting vulnerability in Traveloka 3.14.0
The Traveloka application 3.14.0 for Android exports com.traveloka.android.activity.common.WebViewActivity, leading to the opening of arbitrary URLs, which can inject deceptive content into the UI.
network
high complexity
traveloka CWE-79
2.6
2019-09-21 CVE-2019-16665 Cross-site Scripting vulnerability in Thinksaas 2.91
An issue was discovered in ThinkSAAS 2.91.
network
thinksaas CWE-79
4.3
2019-09-21 CVE-2019-16664 Cross-site Scripting vulnerability in Thinksaas 2.91
An issue was discovered in ThinkSAAS 2.91.
network
thinksaas CWE-79
3.5