A post-authenticated stored XSS was found in MultiUx v.3.1.12.0 via the /multiux/SaveMailbox LastName field.
CWE-79
CVE-2020-1721
A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitize the recovery ID during a key recovery request, enabling a reflected cross-site scripting (XSS) vulnerability. An attacker could trick an authenticated victim into executing specially crafted Javascript code.
CVE-2020-17362
search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS.
CVE-2020-17364
USVN (aka User-friendly SVN) before 1.0.9 allows XSS via SVN logs.
CVE-2020-17372
SugarCRM before 10.1.0 (Q3 2020) allows XSS.
CVE-2020-17147
Dynamics CRM Webclient Cross-site Scripting Vulnerability
