Cross Site Scripting (XSS) exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via the configuration of a user account. An attacker can execute arbitrary script on an unsuspecting user’s browser.
CWE-79
CVE-2018-9120
In Crea8social 2018.2, there is Stored Cross-Site Scripting via a post.
CVE-2018-9121
In Crea8social 2018.2, there is Stored Cross-Site Scripting via a post comment.
CVE-2018-9122
In Crea8social 2018.2, there is Reflected Cross-Site Scripting via the term parameter to the /search URI.
CVE-2018-9123
In Crea8social 2018.2, there is Stored Cross-Site Scripting via a User Profile.
CVE-2018-9130
IBOS 4.4.3 has XSS via a company full name.