• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2021-36738

February 23, 2023 by

The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should migrate to version 3.1.1 of the applicant-mvcbean-cdi-jsp-portlet.war artifact

CVE-2021-36739

February 23, 2023 by

The “first name” and “last name” fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to Cross-Site Scripting (XSS) attacks.

CVE-2021-36746

February 23, 2023 by

Blackboard Learn through 9.1 allows XSS by an authenticated user via the Assignment Instructions HTML editor.

CVE-2021-36747

February 23, 2023 by

Blackboard Learn through 9.1 allows XSS by an authenticated user via the Feedback to Learner form.

CVE-2021-36755

February 23, 2023 by

Nightscout Web Monitor (aka cgm-remote-monitor) 14.2.2 allows XSS via a crafted X-Forwarded-For header.

CVE-2021-36760

February 23, 2023 by

In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback parameter modifying the URL that precedes the callback parameter. Once the username or password reset procedure is completed, the JavaScript code will be executed. (recoverpassword.do also has an open redirect issue for a similar reason.)

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 1407
  • Go to page 1408
  • Go to page 1409
  • Go to page 1410
  • Go to page 1411
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE