The front page of MetInfo 6.0 allows XSS by sending a feedback message to an administrator.
CWE-79
CVE-2018-9986
In Zulip Server versions before 1.7.2, there were XSS issues with the frontend markdown processor.
CVE-2018-9987
In Zulip Server versions 1.5.x, 1.6.x, and 1.7.x before 1.7.2, there was an XSS issue with muting notifications.
CVE-2018-9990
In Zulip Server versions before 1.7.2, there was an XSS issue with stream names in topic typeahead.
CVE-2018-9991
Frog CMS 0.9.5 has XSS via the /admin/?/user/add Name or Username parameter.
CVE-2018-9992
Frog CMS 0.9.5 has XSS via the name field of a new “File” or “Directory” on the admin/?/plugin/file_manager/browse/ screen.