Collabtive 3.1 allows XSS via the manageuser.php?action=profile id parameter.
CWE-79
CVE-2019-8937
HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, and visualizza_tabelle.php.
CVE-2019-8938
VertrigoServ 2.17 allows XSS via the /inc/extensions.php ext parameter.
CVE-2019-8939
data/interfaces/default/history.html in Tautulli 2.1.26 has XSS via a crafted Plex username that is mishandled when constructing the History page.
CVE-2019-8945
Zimbra Collaboration 8.7.x – 8.8.11P2 contains persistent XSS.
CVE-2019-8946
Zimbra Collaboration 8.7.x – 8.8.11P2 contains persistent XSS.
