• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2020-12779

February 26, 2023 by

Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.

CVE-2020-12718

February 26, 2023 by

In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. The protection mechanism can be bypassed by using HTML event handlers such as ontoggle.

CVE-2020-12759

February 26, 2023 by

Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook.

CVE-2020-12683

February 26, 2023 by

Katyshop2 before 2.12 has multiple stored XSS issues.

CVE-2020-12685

February 26, 2023 by

XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote attackers to steal credentials or data via browser JavaScript.

CVE-2020-12696

February 26, 2023 by

The iframe plugin before 4.5 for WordPress does not sanitize a URL.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 902
  • Go to page 903
  • Go to page 904
  • Go to page 905
  • Go to page 906
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE