• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2020-28727

February 26, 2023 by

Cross-site scripting (XSS) exists in SeedDMS 6.0.13 via the folderid parameter to views/bootstrap/class.DropFolderChooser.php.

CVE-2020-28647

February 26, 2023 by

In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim’s browser (XSS).

CVE-2020-28650

February 26, 2023 by

The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard WordPress XSS protection mechanism for the Author and Contributor roles.

CVE-2020-28487

February 26, 2023 by

This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application.

CVE-2020-28455

February 26, 2023 by

This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.

CVE-2020-28456

February 26, 2023 by

The package s-cart/core before 4.4 are vulnerable to Cross-site Scripting (XSS) via the admin panel.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 718
  • Go to page 719
  • Go to page 720
  • Go to page 721
  • Go to page 722
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE