ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter.
CWE-79
CVE-2019-20525
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
CVE-2019-20526
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
CVE-2019-20527
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.
CVE-2019-20528
Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
CVE-2019-20483
An issue was discovered in Viki Vera 4.9.1.26180. An attacker could set a user’s last name to an XSS Payload, and read another user’s cookie and use that to login to the application.
