SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.
CWE-79
CVE-2021-31903
In JetBrains YouTrack before 2021.1.9819, a pull request’s title was sanitized insufficiently, leading to XSS.
CVE-2021-31904
In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.
CVE-2021-31792
XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field
CVE-2021-31794
Settings.aspx?view=About in Directum 5.8.2 allows XSS via the HTTP User-Agent header.
CVE-2021-31803
cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).
