Vulnerabilities (CVE)

Filtered by CWE-79
Total 28117 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-1000151 1 Tera-charts Project 1 Tera-charts 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin tera-charts v1.0
CVE-2016-1000135 1 Hdw-tube Project 1 Hdw-tube 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin hdw-tube v1.2
CVE-2016-1000128 1 Anti-plagiarism Project 1 Anti-plagiarism 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin anti-plagiarism v3.60
CVE-2016-1000130 1 E-search Project 1 E-search 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin e-search v1.0
CVE-2016-1000150 1 Oxil 1 Simplified-content 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin simplified-content v1.0.0
CVE-2016-1000147 1 Recipes-writer Project 1 Recipes-writer 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin recipes-writer v1.0.4
CVE-2016-1000153 1 Tidio-gallery Project 1 Tidio-gallery 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin tidio-gallery v1.1
CVE-2016-1000134 1 Hdw-tube Project 1 Hdw-tube 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin hdw-tube v1.2
CVE-2016-7884 1 Adobe 1 Experience Manager 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Adobe Experience Manager versions 6.1 and earlier have an input validation issue in the DAM create assets that could be used in cross-site scripting attacks.
CVE-2016-7883 1 Adobe 1 Experience Manager 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Adobe Experience Manager version 6.2 has an input validation issue in create Launch wizard that could be used in cross-site scripting attacks.
CVE-2016-7882 1 Adobe 1 Experience Manager 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Adobe Experience Manager versions 6.2 and earlier have an input validation issue in the WCMDebug filter that could be used in cross-site scripting attacks.
CVE-2015-6805 1 Medhabidotcom 1 Mdc Private Message 2016-12-22 3.5 LOW N/A
Cross-site scripting (XSS) vulnerability in the MDC Private Message plugin 1.0.0 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the message field in a private message.
CVE-2015-6672 1 Citrix 2 Netscaler Application Delivery Controller Firmware, Netscaler Gateway Firmware 2016-12-22 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-6506 1 Bestpractical 1 Request Tracker 2016-12-22 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the cryptography interface in Request Tracker (RT) before 4.2.12 allows remote attackers to inject arbitrary web script or HTML via a crafted public key.
CVE-2015-5691 1 Symantec 1 Web Gateway 2016-12-22 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in PHP scripts in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, as demonstrated an attack against admin_messages.php.
CVE-2015-5625 1 Opendocman 1 Opendocman 2016-12-22 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in OpenDocMan before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the redirection parameter.
CVE-2015-5528 1 Wpbeginner 1 Floating Social Bar 2016-12-22 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the save_order function in class-floating-social-bar.php in the Floating Social Bar plugin before 1.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the items[] parameter in an fsb_save_order action to wp-admin/admin-ajax.php.
CVE-2015-5481 1 Dev4press 1 Gd Bbpress Attachments 2016-12-22 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.
CVE-2015-5475 1 Bestpractical 1 Request Tracker 2016-12-22 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Request Tracker (RT) 4.x before 4.2.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) user and (2) group rights management pages.
CVE-2015-4552 1 Mybb 1 Mybb 2016-12-22 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the quick edit function in xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the content of a post.