Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2021-45474

In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.

CVE
#xss#java
CVE-2021-45473: ⚓ T294693 XSS on page information Wikibase central description

In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sidebar).

CVE-2021-45472: ⚓ T297570 XSS in Wikibase using formatter URL

In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.

CVE-2021-44543: www.privoxy.org Git - privoxy.git/commit

An XSS vulnerability was found in Privoxy which was fixed in cgi_error_no_template() by encode the template name when Privoxy is configured to servce the user-manual itself.

CVE-2020-20425: s-cms Government station building system exists XSS · Issue #1 · Str1am/vulnerability

S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in the search function.

CVE-2020-20426: government.com - This website is for sale! - government Resources and Information.

S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in /function/booksave.php.

CVE-2020-20605: Blog CMS V1.0 feedback have a xss vulnerability · Issue #4 · xuzijia/blog

Blog CMS v1.0 contains a cross-site scripting (XSS) vulnerability in the /controller/CommentAdminController.java component.

CVE-2020-20597: lemon 存在存储型XSS · Issue #198 · xuhuisheng/lemon

A cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML.

CVE-2020-20600: MetInfo7.0 beta stored Cross Site Scripting Vulnerability · Issue #2 · alixiaowei/cve_test

MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn.