• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2020-15500

February 26, 2023 by

An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected unsanitized in an HTTP response for the application’s main page, causing reflected XSS.

CVE-2020-15514

February 26, 2023 by

The jh_captcha extension through 2.1.3, and 3.x through 3.0.2, for TYPO3 allows XSS.

CVE-2020-15400

February 26, 2023 by

CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.

CVE-2020-15364

February 26, 2023 by

The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.

CVE-2020-15299

February 26, 2023 by

A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is executed in the victim’s browser.

CVE-2020-15307

February 26, 2023 by

Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to create a custom field with a crafted field name.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 860
  • Go to page 861
  • Go to page 862
  • Go to page 863
  • Go to page 864
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE