Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2017-12-20 CVE-2017-17752 Cross-site Scripting vulnerability in Codecrafters Ability Mail Server 3.3.2
Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI).
network
low complexity
codecrafters CWE-79
6.1
2017-12-20 CVE-2017-4940 Cross-site Scripting vulnerability in VMWare Esxi 6.0/6.5
The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-site scripting (XSS).
network
low complexity
vmware CWE-79
6.1
2017-12-20 CVE-2017-17792 Cross-site Scripting vulnerability in Blogotext Project Blogotext
Cross site scripting (XSS) vulnerability in the markup_clean_href function in inc/conv.php in BlogoText through 3.7.6 allows remote attackers to inject arbitrary JavaScript via a comment.
network
low complexity
blogotext-project CWE-79
6.1
2017-12-20 CVE-2017-17780 Cross-site Scripting vulnerability in Mediaburst products
The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php.
network
low complexity
mediaburst CWE-79
6.1
2017-12-20 CVE-2017-17778 Cross-site Scripting vulnerability in Paid to Read Script Project Paid to Read Script 2.0.5
Paid To Read Script 2.0.5 has XSS via the referrals.php tier parameter or the admin/userview.php uid parameter.
network
low complexity
paid-to-read-script-project CWE-79
4.8
2017-12-20 CVE-2017-17775 Cross-site Scripting vulnerability in Piwigo 2.9.2
Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.
network
low complexity
piwigo CWE-79
6.1
2017-12-19 CVE-2017-17753 Cross-site Scripting vulnerability in Csv-Import-Export Project Csv-Import-Export 1.0.0
Multiple cross-site scripting (XSS) vulnerabilities in the esb-csv-import-export plugin through 1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cie_type, (2) cie_import, (3) cie_update, or (4) cie_ignore parameter to includes/admin/views/esb-cie-import-export-page.php.
network
low complexity
csv-import-export-project CWE-79
6.1
2017-12-19 CVE-2017-17744 Cross-site Scripting vulnerability in Webdesi9 Custom MAP 1.0/1.0.1/1.1
A cross-site scripting (XSS) vulnerability in the custom-map plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter to view/advancedsettings.php.
network
low complexity
webdesi9 CWE-79
6.1
2017-12-19 CVE-2017-17719 Cross-site Scripting vulnerability in Olyos Wp-Concours
A cross-site scripting (XSS) vulnerability in the wp-concours plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the result_message parameter to includes/concours_page.php.
network
low complexity
olyos CWE-79
6.1
2017-12-19 CVE-2013-6465 Cross-site Scripting vulnerability in Redhat Jbpm 6.0.0
Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HTML via vectors related to task name html inputs.
network
low complexity
redhat CWE-79
5.4