WordPress before 5.2.3 allows XSS in stored comments.
CWE-79
CVE-2019-16219
WordPress before 5.2.3 allows XSS in shortcode previews.
CVE-2019-16221
WordPress before 5.2.3 allows reflected XSS in the dashboard.
CVE-2019-16222
WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks.
CVE-2019-16223
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
CVE-2019-16238
Afterlogic Aurora through 8.3.9-build-a3 has XSS that can be leveraged for session hijacking by retrieving the session cookie from the administrator login.
