• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2019-11547

February 26, 2023 by

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn’t escaped, which could potentially lead to XSS issues.

CVE-2019-11548

February 26, 2023 by

An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint.

CVE-2019-11556

February 26, 2023 by

Pagure before 5.6 allows XSS via the templates/blame.html blame view.

CVE-2019-11559

February 26, 2023 by

A reflected Cross-site scripting (XSS) vulnerability in HRworks V 1.16.1 allows remote attackers to inject arbitrary web script or HTML via the URL parameter to the Login component.

CVE-2019-11504

February 26, 2023 by

Zotonic before version 0.47 has mod_admin XSS.

CVE-2019-11507

February 26, 2023 by

In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1210
  • Go to page 1211
  • Go to page 1212
  • Go to page 1213
  • Go to page 1214
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE