HongCMS 3.0.0 has XSS via the install/index.php dbusername parameter.
CWE-79
CVE-2019-17610
HongCMS 3.0.0 has XSS via the install/index.php dbpassword parameter.
CVE-2019-17611
HongCMS 3.0.0 has XSS via the install/index.php tableprefix parameter.
CVE-2019-17625
There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for Node.js and Electron, such as an exec of OS commands within the onerror attribute of an IMG element.
CVE-2019-17629
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the “file manager > upload images” screen.
CVE-2019-17630
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the “News > Add Article” screen.
