Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-12-20 | CVE-2017-17752 | Cross-site Scripting vulnerability in Codecrafters Ability Mail Server 3.3.2 Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). | 6.1 |
2017-12-20 | CVE-2017-4940 | Cross-site Scripting vulnerability in VMWare Esxi 6.0/6.5 The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-site scripting (XSS). | 6.1 |
2017-12-20 | CVE-2017-17792 | Cross-site Scripting vulnerability in Blogotext Project Blogotext Cross site scripting (XSS) vulnerability in the markup_clean_href function in inc/conv.php in BlogoText through 3.7.6 allows remote attackers to inject arbitrary JavaScript via a comment. | 6.1 |
2017-12-20 | CVE-2017-17780 | Cross-site Scripting vulnerability in Mediaburst products The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. | 6.1 |
2017-12-20 | CVE-2017-17778 | Cross-site Scripting vulnerability in Paid to Read Script Project Paid to Read Script 2.0.5 Paid To Read Script 2.0.5 has XSS via the referrals.php tier parameter or the admin/userview.php uid parameter. | 4.8 |
2017-12-20 | CVE-2017-17775 | Cross-site Scripting vulnerability in Piwigo 2.9.2 Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request. | 6.1 |
2017-12-19 | CVE-2017-17753 | Cross-site Scripting vulnerability in Csv-Import-Export Project Csv-Import-Export 1.0.0 Multiple cross-site scripting (XSS) vulnerabilities in the esb-csv-import-export plugin through 1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cie_type, (2) cie_import, (3) cie_update, or (4) cie_ignore parameter to includes/admin/views/esb-cie-import-export-page.php. | 6.1 |
2017-12-19 | CVE-2017-17744 | Cross-site Scripting vulnerability in Webdesi9 Custom MAP 1.0/1.0.1/1.1 A cross-site scripting (XSS) vulnerability in the custom-map plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter to view/advancedsettings.php. | 6.1 |
2017-12-19 | CVE-2017-17719 | Cross-site Scripting vulnerability in Olyos Wp-Concours A cross-site scripting (XSS) vulnerability in the wp-concours plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the result_message parameter to includes/concours_page.php. | 6.1 |
2017-12-19 | CVE-2013-6465 | Cross-site Scripting vulnerability in Redhat Jbpm 6.0.0 Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HTML via vectors related to task name html inputs. | 5.4 |