phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php.
CWE-79
CVE-2020-12646
OX App Suite 7.10.3 and earlier allows XSS via text/x-javascript, text/rdf, or a PDF document.
CVE-2020-12648
A cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier allows remote attackers to inject arbitrary web script when configured in classic editing mode.
CVE-2020-12670
XSS exists in Webmin 1.941 and earlier affecting the Save function of the Read User Email Module / mailboxes Endpoint when attempting to save HTML emails. This module parses any output without sanitizing SCRIPT elements, as opposed to the View function, which sanitizes the input correctly. A malicious user can send any JavaScript payload into the message body and execute it if the user decides to save that email.
CVE-2020-12677
An issue was discovered in Progress MOVEit Automation Web Admin. A Web Admin application endpoint failed to adequately sanitize malicious input, which could allow an unauthenticated attacker to execute arbitrary code in a victim’s browser, aka XSS. This affects 2018 – 2018.0 prior to 2018.0.3, 2018 SP1 – 2018.2 prior to 2018.2.3, 2018 SP2 – 2018.3 prior to 2018.3.7, 2019 – 2019.0 prior to 2019.0.3, 2019.1 – 2019.1 prior to 2019.1.2, and 2019.2 – 2019.2 prior to 2019.2.2.
CVE-2020-12679
A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 allows remote attackers to inject arbitrary JavaScript and HTML via the PATH_INFO to home.php.
