Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2017-05-04 CVE-2017-8778 Cross-site Scripting vulnerability in Gitlab
GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment or avatar that is an SVG document.
network
low complexity
gitlab CWE-79
6.1
2017-05-04 CVE-2017-8780 Cross-site Scripting vulnerability in Genixcms 1.0.2
GeniXCMS 1.0.2 has XSS triggered by a comment that is mishandled during a publish operation by an administrator, as demonstrated by a malformed P element.
network
low complexity
genixcms CWE-79
4.8
2017-05-04 CVE-2017-8763 Cross-site Scripting vulnerability in Telaxius Epesi
Cross-site scripting (XSS) vulnerability in modules/Base/Box/check_for_new_version.php in EPESI in Telaxus/EPESI 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URI that lacks the cid parameter.
network
low complexity
telaxius CWE-79
6.1
2017-05-03 CVE-2017-8762 Cross-site Scripting vulnerability in Genixcms 1.0.2
GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element.
network
low complexity
genixcms CWE-79
5.4
2017-05-03 CVE-2015-9057 Cross-site Scripting vulnerability in Proxmox Mail Gateway
Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allow remote attackers to inject arbitrary web script or HTML via multiple parameters, related to /users/index.htm, /quarantine/spam/manage.htm, /quarantine/spam/whitelist.htm, /queues/mail/index/, /system/ssh.htm, /queues/mail/?domain=, and /quarantine/virus/manage.htm.
network
low complexity
proxmox CWE-79
6.1
2017-05-03 CVE-2017-7430 Cross-site Scripting vulnerability in multiple products
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.
network
low complexity
novell netiq CWE-79
6.1
2017-05-01 CVE-2017-8376 Cross-site Scripting vulnerability in Genixcms 1.0.2
GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.
network
low complexity
genixcms CWE-79
5.4
2017-05-01 CVE-2017-5631 Cross-site Scripting vulnerability in KMC Information Systems Caseaware
An issue was discovered in KMCIS CaseAware.
network
low complexity
kmc-information-systems CWE-79
6.1
2017-05-01 CVE-2017-8384 Cross-site Scripting vulnerability in Craftcms Craft CMS
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based.
network
low complexity
craftcms CWE-79
6.1
2017-04-28 CVE-2017-2151 Cross-site Scripting vulnerability in Booking Calendar Project Booking Calendar
Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
booking-calendar-project CWE-79
6.1