• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2020-26166

February 26, 2023 by

The file upload functionality in qdPM 9.1 doesn’t check the file description, which allows remote authenticated attackers to inject web script or HTML via the attachments info parameter, aka XSS. This can occur during creation of a ticket, project, or task.

CVE-2020-26110

February 26, 2023 by

cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564).

CVE-2020-26111

February 26, 2023 by

cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566).

CVE-2020-26113

February 26, 2023 by

cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569).

CVE-2020-26114

February 26, 2023 by

cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573).

CVE-2020-26115

February 26, 2023 by

cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574).

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 740
  • Go to page 741
  • Go to page 742
  • Go to page 743
  • Go to page 744
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE