VNote 2.2 has XSS via a new text note.
CWE-79
CVE-2019-8425
includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
CVE-2019-8426
skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter.
CVE-2019-8432
In CmsEasy 7.0, there is XSS via the ckplayer.php url parameter.
CVE-2019-8434
In CmsEasy 7.0, there is XSS via the ckplayer.php autoplay parameter.
CVE-2019-8435
admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.
