CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL.
CWE-79
CVE-2019-15501
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
CVE-2019-15510
ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role.
CVE-2019-15476
Former before 4.2.1 has XSS via a checkbox value.
CVE-2019-15477
Jooby before 1.6.4 has XSS via the default error handler.
CVE-2019-15478
Status Board 1.1.81 has reflected XSS via logic.ts.
