The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field.
CWE-79
CVE-2021-27370
The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
CVE-2021-27371
The Contact page in Monica 2.19.1 allows stored XSS via the Description field.
CVE-2021-27401
The Join Meeting page of Mitel MiCollab Web Client before 9.2 FP2 could allow an attacker to access (view and modify) user data by executing arbitrary code due to insufficient input validation, aka Cross-Site Scripting (XSS).
CVE-2021-27403
Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow cgi-bin/te_acceso_router.cgi curWebPage XSS.
CVE-2021-27279
MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode).
