Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-04-18 | CVE-2018-9987 | Cross-site Scripting vulnerability in Zulip Server In Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2, there was an XSS issue with muting notifications. | 6.1 |
2018-04-18 | CVE-2018-9986 | Cross-site Scripting vulnerability in Zulip Server In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor. | 6.1 |
2018-04-18 | CVE-2018-8071 | Cross-site Scripting vulnerability in Mautic Mautic before v2.13.0 has stored XSS via a theme config file. | 6.1 |
2018-04-17 | CVE-2018-5431 | Cross-site Scripting vulnerability in Tibco products The domain designer component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which may allow, in the context of a non-default permissions configuration, persisted cross-site scripting (XSS) attacks. | 5.4 |
2018-04-17 | CVE-2018-1445 | Cross-site Scripting vulnerability in IBM Websphere Portal IBM WebSphere Portal 8.0.0 through 8.0.0.1, 8.5, and 9.0 is vulnerable to cross-site scripting. | 5.4 |
2018-04-17 | CVE-2018-10183 | Cross-site Scripting vulnerability in Bigtreecms Bigtree CMS 4.2.22 An issue was discovered in BigTree 4.2.22. | 6.1 |
2018-04-17 | CVE-2017-18102 | Cross-site Scripting vulnerability in Atlassian Jira Server The wiki markup component of atlassian-renderer from version 8.0.0 before version 8.0.22 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in nested wiki markup. | 5.4 |
2018-04-16 | CVE-2018-10138 | Cross-site Scripting vulnerability in Catalooksupport .Netstore 7.2.8 The CATALooK.netStore module through 7.2.8 for DNN (formerly DotNetNuke) allows XSS via the /ViewEditGoogleMaps.aspx PortalID or CATSkin parameter, or the /ImageViewer.aspx link or desc parameter. | 6.1 |
2018-04-16 | CVE-2018-10136 | Cross-site Scripting vulnerability in Iscripts Uberforx 2.2 iScripts UberforX 2.2 has Stored XSS in the "manage_settings" section of the Admin Panel via a value field to the /cms?section=manage_settings&action=edit URI. | 6.1 |
2018-04-16 | CVE-2018-10135 | Cross-site Scripting vulnerability in Iscripts Eswap 2.4 iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel. | 6.1 |