• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2019-14670

February 26, 2023 by

Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name field. The JavaScript code is executed during rule-from-bill creation.

CVE-2019-14672

February 26, 2023 by

Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field. The JavaScript code is executed upon an error condition during a visit to the account show page.

CVE-2019-14696

February 26, 2023 by

Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.

CVE-2019-14652

February 26, 2023 by

explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certain circumstances.

CVE-2019-14653

February 26, 2023 by

pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.

CVE-2019-14546

February 26, 2023 by

An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending an email when a malicious payload was inserted inside the Email Signature in the Preference page. The attacker could insert malicious JavaScript inside his email signature, which fires when the victim replies or forwards the mail, thus helping him steal victims’ cookies (hence compromising their accounts).

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1163
  • Go to page 1164
  • Go to page 1165
  • Go to page 1166
  • Go to page 1167
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE