• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2020-13476

February 26, 2023 by

NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module.

CVE-2020-13480

February 26, 2023 by

Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the “send email” feature.

CVE-2020-13483

February 26, 2023 by

The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI.

CVE-2020-13487

February 26, 2023 by

The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for all users. An administrator can exploit this at the wp-admin/post.php?action=edit URI.

CVE-2020-13418

February 26, 2023 by

OpenIAM before 4.2.0.3 allows XSS in the Add New User feature.

CVE-2020-13423

February 26, 2023 by

Form Builder 2.1.0 for Magento has multiple XSS issues that can be exploited against Magento 2 admin accounts via the Current_url or email field, or the User-Agent HTTP header.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 891
  • Go to page 892
  • Go to page 893
  • Go to page 894
  • Go to page 895
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE