WordPress before 5.5.2 allows XSS associated with global variables.
CWE-79
CVE-2020-28038
WordPress before 5.5.2 allows stored XSS via post slugs.
CVE-2020-27980
Genexis Platinum-4410 P4410-V2-1.28 devices allow stored XSS in the WLAN SSID parameter. This could allow an attacker to perform malicious actions in which the XSS popup will affect all privileged users.
CVE-2020-27982
IceWarp 11.4.5.0 allows XSS via the language parameter.
CVE-2020-27988
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
CVE-2020-27989
Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).
