CMS Made Simple 2.2.10 has XSS via the m1_name parameter in “Add Article” under Content -> Content Manager -> News.
CWE-79
CVE-2019-11132
Cross site scripting in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow a privileged user to potentially enable escalation of privilege via network access.
CVE-2019-1105
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka ‘Outlook for Android Spoofing Vulnerability’.
CVE-2019-11084
GAuth 0.9.9 beta has stored XSS that shows a popup repeatedly and discloses cookies.
CVE-2019-11002
In Materialize through 1.0.0, XSS is possible via the Tooltip feature.
CVE-2019-11003
In Materialize through 1.0.0, XSS is possible via the Autocomplete feature.
