The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
CWE-79
CVE-2019-15898
Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page.
CVE-2019-15935
Intesync Solismed 3.3sp has XSS.
CVE-2019-15842
The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.
CVE-2019-15848
JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
CVE-2019-15864
The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has XSS.
