Filtered by CWE-79
Total 43851 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-12711 1 Joomla 1 Joomla\! 2024-11-21 N/A
An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9. In some cases, the link of the current language might contain unescaped HTML special characters. This may lead to reflective XSS via injection of arbitrary parameters and/or values on the current page URL.
CVE-2018-12705 1 Digisol 2 Dg-br4000ng, Dg-br4000ng Firmware 2024-11-21 N/A
DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).
CVE-2018-12696 1 Mao10 1 Mao10cms 2024-11-21 N/A
mao10cms 6 allows XSS via the article page.
CVE-2018-12695 1 Mao10 1 Mao10cms 2024-11-21 N/A
mao10cms 6 allows XSS via the m=bbs&a=index page.
CVE-2018-12672 1 Sv3c 4 H.264 Poe Ip Camera Firmware, Sv-b01poe-1080p-l, Sv-b11vpoe-1080p-l and 1 more 2024-11-21 N/A
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B) does not perform proper validation on user-supplied input and is vulnerable to cross-site scripting attacks. If proper authorization was implemented, this vulnerability could be leveraged to perform actions on behalf of another user or the administrator.
CVE-2018-12658 1 Slims Project 1 Slims 2024-11-21 6.1 Medium
Reflected Cross-Site Scripting (XSS) exists in the Stock Take module in SLiMS 8 Akasia 8.3.1 via an admin/modules/stock_take/index.php?keywords= URI.
CVE-2018-12657 1 Slims Akasia Project 1 Slims Akasia 2024-11-21 N/A
Reflected Cross-Site Scripting (XSS) exists in the Master File module in SLiMS 8 Akasia 8.3.1 via an admin/modules/master_file/rda_cmc.php?keywords= URI.
CVE-2018-12656 1 Slims Akasia Project 1 Slims Akasia 2024-11-21 N/A
Reflected Cross-Site Scripting (XSS) exists in the Membership module in SLiMS 8 Akasia 8.3.1 via an admin/modules/membership/index.php?keywords= URI.
CVE-2018-12655 1 Slims Akasia Project 1 Slims Akasia 2024-11-21 N/A
Reflected Cross-Site Scripting (XSS) exists in the Circulation module in SLiMS 8 Akasia 8.3.1 via an admin/modules/circulation/loan_rules.php?keywords= URI, a related issue to CVE-2017-7242.
CVE-2018-12654 1 Slims Akasia Project 1 Slims Akasia 2024-11-21 N/A
Reflected Cross-Site Scripting (XSS) exists in the Bibliography module in SLiMS 8 Akasia 8.3.1 via an admin/modules/bibliography/index.php?keywords= URI.
CVE-2018-12638 1 Bose 1 Soundtouch 2024-11-21 N/A
An issue was discovered in the Bose Soundtouch app 18.1.4 for iOS. There is no frontend input validation of the device name. A malicious device name can execute JavaScript on the registered Bose User Account if a speaker has been connected to the app.
CVE-2018-12627 1 Eventum Project 1 Eventum 2024-11-21 N/A
An issue was discovered in Eventum 3.5.0. /htdocs/list.php has XSS via the show_notification_list_issues or show_authorized_issues parameter.
CVE-2018-12626 1 Eventum Project 1 Eventum 2024-11-21 N/A
An issue was discovered in Eventum 3.5.0. /htdocs/popup.php has XSS via the cat parameter.
CVE-2018-12625 1 Eventum Project 1 Eventum 2024-11-21 N/A
An issue was discovered in Eventum 3.5.0. /htdocs/validate.php has XSS via the values parameter.
CVE-2018-12624 1 Eventum Project 1 Eventum 2024-11-21 N/A
An issue was discovered in Eventum 3.5.0. /htdocs/post_note.php has XSS via the garlic_prefix parameter.
CVE-2018-12623 1 Eventum Project 1 Eventum 2024-11-21 N/A
An issue was discovered in Eventum 3.5.0. htdocs/switch.php has XSS via the current_page parameter.
CVE-2018-12622 1 Eventum Project 1 Eventum 2024-11-21 N/A
An issue was discovered in Eventum 3.5.0. htdocs/ajax/update.php has XSS via the field_name parameter.
CVE-2018-12611 1 Open-xchange 1 Open-xchange Appsuite 2024-11-21 N/A
OX App Suite 7.8.4 and earlier allows Directory Traversal.
CVE-2018-12607 1 Gitlab 1 Gitlab 2024-11-21 N/A
An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts feature contained a persistent XSS issue due to a lack of output encoding.
CVE-2018-12606 1 Gitlab 1 Gitlab 2024-11-21 N/A
An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific markdown feature.