An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the web management console are vulnerable to stored XSS, as demonstrated by the configuration of the UI language.
CWE-79
CVE-2019-20493
cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).
CVE-2019-20497
cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).
CVE-2019-20511
ERPNext 11.1.47 allows blog?blog_category= Frame Injection.
CVE-2019-20512
Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS.
CVE-2019-20513
Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
