Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2017-10-06 CVE-2015-2148 Cross-site Scripting vulnerability in PHPbugtracker Project PHPbugtracker
Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.2 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
network
low complexity
phpbugtracker-project CWE-79
4.8
2017-10-06 CVE-2015-2145 Cross-site Scripting vulnerability in PHPbugtracker Project PHPbugtracker
Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
network
low complexity
phpbugtracker-project CWE-79
4.8
2017-10-06 CVE-2015-2144 Cross-site Scripting vulnerability in PHPbugtracker Project PHPbugtracker
Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) project name parameter to project.php; the (2) use_js parameter to user.php; the (3) use_js parameter to group.php; the (4) Description parameter to status.php; the (5) Description parameter to severity.php; the (6) Regex parameter to os.php; or the (7) Name parameter to database.php.
network
low complexity
phpbugtracker-project CWE-79
4.8
2017-10-06 CVE-2014-8957 Cross-site Scripting vulnerability in Openkm 6.4.18
Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary web script or HTML via the Tasks parameter.
network
low complexity
openkm CWE-79
5.4
2017-10-06 CVE-2014-8758 Cross-site Scripting vulnerability in Tech-Banker Gallery Bank
Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70for WordPress allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in the gallery_album_sorting page to wp-admin/admin.php.
network
low complexity
tech-banker CWE-79
6.1
2017-10-06 CVE-2014-8492 Cross-site Scripting vulnerability in Cozmoslabs Profile Builder
Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site_name, (2) message, or (3) site_url parameter.
network
low complexity
cozmoslabs CWE-79
6.1
2017-10-06 CVE-2014-7240 Cross-site Scripting vulnerability in Formget Easy Contact Form Solution
Cross-site scripting (XSS) vulnerability in the Easy Contact Form Solution plugin before 1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the value parameter in a master_response action to wp-admin/admin-ajax.php.
network
low complexity
formget CWE-79
6.1
2017-10-05 CVE-2017-13994 Cross-site Scripting vulnerability in Loytec Lvis-3Me Firmware 6.1.1
A Cross-site Scripting issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0.
network
low complexity
loytec CWE-79
6.1
2017-10-05 CVE-2017-1522 Cross-site Scripting vulnerability in IBM Content Navigator 2.0.3.8/3.0.0/3.0.1
IBM Content Navigator & CMIS 2.0.3, 3.0.0, and 3.0.1 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4
2017-10-05 CVE-2017-14354 Cross-site Scripting vulnerability in HP Ucmdb Foundation Software
A remote cross-site scripting vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33 could be remotely exploited to allow cross-site scripting.
network
low complexity
hp CWE-79
6.1