Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.
CWE-79
CVE-2019-15532
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
CVE-2019-15539
The proj_doc_edit_page.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed when editing the document’s page.
CVE-2019-15482
selectize-plugin-a11y before 1.1.0 has XSS via the msg field.
CVE-2019-15483
Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.
CVE-2019-15484
Bolt before 3.6.10 has XSS via an image’s alt or title field.
