Skip to main content

CWE archive

CWE-80 CVEs

Programmatic archive

559 CVEs tagged with CWE-8016 Critical, 86 High, 375 Medium, 80 Low, 2 Unrated.

CVE-2017-20026

Published Jun 9, 2022

A vulnerability has been found in HumHub up to 1.0.1 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross sit…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-25070

Published Jun 9, 2022

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WolfCMS up to 0.8.3.1. It has been rated as problematic. This issue affects some unknown processing of the file /wolfc…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-36544

Published Jun 8, 2022

A vulnerability has been found in SialWeb CMS and classified as problematic. This vulnerability affects unknown code of the component Search Handler. The manipulation leads to cro…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-29258

Published May 31, 2022

XWiki Platform Filter UI provides a generic user interface to convert from a XWiki Filter input stream to an output stream with settings for each stream. Starting with versions 6.…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-20765

Published May 27, 2022

A vulnerability in the web applications of Cisco UCS Director could allow an authenticated, remote attacker to conduct a cross-site scripting attack on an affected system. This vu…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29252

Published May 25, 2022

XWiki Platform Wiki UI Main Wiki is a package for managing subwikis. Starting with version 5.3-milestone-2, XWiki Platform Wiki UI Main Wiki contains a possible cross-site scripti…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29251

Published May 25, 2022

XWiki Platform Flamingo Theme UI is a tool that allows customization and preview of any Flamingo-based skin. Starting with versions 6.2.4 and 6.3-rc-1, a possible cross-site scrip…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21145

Published Apr 14, 2022

A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can lead to arbitra…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0989

Published Apr 11, 2022

An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load images that hide malware for example from passing maliciou…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25620

Published Mar 30, 2022

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Group Functionality of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-10001

Published Mar 28, 2022

A vulnerability, which was classified as problematic, has been found in Pro2col Stingray FTS. The manipulation of the argument Username leads to cross site scripting. The attack m…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-5003

Published Mar 28, 2022

A vulnerability was found in ISS BlackICE PC Protection. It has been rated as problematic. Affected by this issue is the Update Handler. The manipulation with an unknown input lea…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1002

Published Mar 18, 2022

Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to inv…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-24749

Published Mar 14, 2022

Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-site scripting (XSS) code in t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37195

Published Jan 11, 2022

A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V1…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39348

Published Oct 21, 2021

The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom_profile parameter found in the ~/inc/admin/views/backend-u…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32735

Published Jul 2, 2021

Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in the pages and files section for example) displayed HTML in p…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36196

Published Jul 1, 2021

A stored XSS vulnerability has been reported to affect QNAP NAS running QuLog Center. If exploited, this vulnerability allows attackers to inject malicious code. This issue affect…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32719

Published Jun 28, 2021

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_fed…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort
Showing 476-500 of 559 CVEsPage 20 of 23