Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cross-site scripting vulnerabilities and exploits
(subscribe to this query)
435
VMScore
CVE-2018-11404
DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.
Domainmod Domainmod 4.09.03
1 EDB exploit
435
VMScore
CVE-2011-1838
Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki prior to 5.0.2 allow remote malicious users to inject arbitrary web script or HTML via the origurl parameter to a (1) view script or (2) login script.
Twiki Twiki 4.1.1
Twiki Twiki 4.0.1
Twiki Twiki 4.2.3
Twiki Twiki 4.2.4
Twiki Twiki 4.3.0
Twiki Twiki 4.3.2
Twiki Twiki 4.0.3
Twiki Twiki 4.0.4
Twiki Twiki 4.2.1
Twiki Twiki 4.2.0
Twiki Twiki 4.0.0
Twiki Twiki 4.5.0
Twiki Twiki 4.1.0
Twiki Twiki 4.3.1
Twiki Twiki 5.0.0
Twiki Twiki 4.2.2
Twiki Twiki
Twiki Twiki 4.0.2
Twiki Twiki 4.0.5
Twiki Twiki 4.1.2
1 EDB exploit
435
VMScore
CVE-2018-19136
DomainMOD up to and including 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.
Domainmod Domainmod
1 EDB exploit
355
VMScore
CVE-2018-7465
An XSS issue exists in VirtueMart prior to 3.2.14. All the textareas in the backend of the plugin can be closed by simply adding </textarea> to the value and saving the product/config. By editing back the product/config, the editor's browser will execute everything aft...
Virtuemart Virtuemart
1 EDB exploit
355
VMScore
CVE-2018-11332
Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote malicious users to inject arbitrary web script or HTML via a crafted site name to the manager/processors/sav...
Clippercms Clippercms 1.3.3
1 EDB exploit
355
VMScore
CVE-2018-11403
DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.
Domainmod Domainmod 4.09.03
1 EDB exploit
355
VMScore
CVE-2019-15814
Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or HTML.
Sentrifugo Sentrifugo 3.2
1 EDB exploit
312
VMScore
CVE-2018-19752
DomainMOD up to and including 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.
Domainmod Domainmod
435
VMScore
CVE-2013-2750
Cross-site scripting (XSS) vulnerability in e107_plugins/content/handlers/content_preset.php in e107 prior to 1.0.3 allows remote malicious users to inject arbitrary web script or HTML via the query string.
E107 E107 0.7.10
E107 E107 0.7.7
E107 E107 0.7.13
E107 E107 0.7.4
E107 E107 0.7.26
E107 E107 1.0.1
E107 E107 0.7.14
E107 E107 0.7.5
E107 E107 0.7.2
E107 E107 0.7.11
E107 E107 0.7.1
E107 E107 0.7.19
E107 E107 0.7.16
E107 E107 0.7.15
E107 E107 0.7.22
E107 E107 0.7.12
E107 E107 0.7.17
E107 E107 0.7.8
E107 E107 0.7.20
E107 E107 0.7.9
E107 E107 0.7.0
E107 E107 0.7.18
1 EDB exploit
NA
CVE-2023-36163
Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote malicious user to execute arbitrary code via a crafted script to the mc parameter of the URL.
Buildagate Project Buildagate 5
1 EDB exploit
1 Github repository
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »