Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2018-10-30 CVE-2018-17782 Cross-site Scripting vulnerability in Mantisbt
A cross-site scripting (XSS) vulnerability in the Manage Filters page (manage_filter_page.php) in MantisBT 2.1.0 through 2.17.1 allows remote attackers (if access rights permit it) to inject arbitrary code (if CSP settings permit it) through a crafted project name.
network
low complexity
mantisbt CWE-79
5.4
2018-10-30 CVE-2018-18841 Cross-site Scripting vulnerability in Sem-Cms Semcms 3.4
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexkey parameter.
network
low complexity
sem-cms CWE-79
4.8
2018-10-30 CVE-2018-18840 Cross-site Scripting vulnerability in Sem-Cms Semcms 3.4
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter.
network
low complexity
sem-cms CWE-79
5.4
2018-10-30 CVE-2018-18825 Cross-site Scripting vulnerability in Pagoda Linux Project Pagoda Linux 6.0
Pagoda Linux panel V6.0 has XSS via the verification code associated with an invalid account login.
network
low complexity
pagoda-linux-project CWE-79
6.1
2018-10-29 CVE-2018-1767 Cross-site Scripting vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Cachemonitor is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2018-10-29 CVE-2018-1766 Cross-site Scripting vulnerability in IBM Rational Team Concert
IBM Team Concert (RTC) 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2018-10-29 CVE-2018-18783 Cross-site Scripting vulnerability in Sem-Cms Semcms 3.4
XSS was discovered in SEMCMS V3.4 via the semcms_remail.php?type=ok umail parameter.
network
low complexity
sem-cms CWE-79
6.1
2018-10-29 CVE-2018-18782 Cross-site Scripting vulnerability in Dedecms 5.7
Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.
network
low complexity
dedecms CWE-79
6.1
2018-10-29 CVE-2018-18781 Cross-site Scripting vulnerability in Dedecms 5.7
DedeCMS 5.7 SP2 allows XSS via the /member/uploads_select.php f or keyword parameter.
network
low complexity
dedecms CWE-79
6.1
2018-10-29 CVE-2018-18745 Cross-site Scripting vulnerability in Sem-Cms Semcms 3.4
An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Menu.php?lgid=1 during editing.
network
low complexity
sem-cms CWE-79
4.8