Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
CWE-79
CVE-2019-17222
An issue was discovered on Intelbras WRN 150 1.0.17 devices. There is stored XSS in the Service Name tab of the WAN configuration screen, leading to a denial of service (inability to change the configuration).
CVE-2019-17223
There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.
CVE-2019-17225
Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an “Admin Member JSON Update” issue.
CVE-2019-17226
CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field.
CVE-2019-17229
includes/options.php in the motors-car-dealership-classified-listings (aka Motors – Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues.
