Cross-Site Scripting

Cross-Site Scripting (XSS) vulnerabilities allow attackers to inject malicious scripts into web pages viewed by other users. This can lead to session hijacking, credential theft, and phishing attacks.

Total CVEs

110

Typical Severity

MEDIUM

Category

General

Understanding Cross-Site Scripting

Detailed information about this vulnerability type.

How to Identify

  • Review security advisories
  • Perform regular security testing

Prevention Best Practices

  • Follow security best practices
  • Keep systems updated

Cross-Site Scripting CVEs (110)

DescriptionVendor / ProductExploit Status
CVE-2018-126536.1

An attacker can inject harmful JavaScript code into the Adrenalin HRMS system, which can then be executed in the browsers of users who view the affected report. This vulnerability requires the attacker to manipulate the 'ReportId' parameter on a specific page, allowing them to target users without needing to authenticate.

myadrenalinadrenalin
Exploit Available
about 7 years agoMar 25, 2019
CVE-2018-126526.1

This vulnerability allows an attacker to inject malicious JavaScript into the Adrenalin HRMS software, which can then be executed in the browsers of users who visit a specially crafted link. To exploit this, the attacker needs to trick users into clicking on a link that includes their malicious code in the parameters of the request.

myadrenalinadrenalin
Exploit Available
about 7 years agoMar 25, 2019
CVE-2018-126516.1

This vulnerability allows an attacker to inject malicious JavaScript code into the HR management software, which can then be executed in the browsers of users who view the affected page. It requires the attacker to trick a user into clicking a specially crafted link that includes the harmful code in the search parameters.

myadrenalinhuman resource management software
Exploit Available
over 7 years agoDec 20, 2018
CVE-2018-126506.1

This vulnerability allows an attacker to inject malicious scripts into the Adrenalin HRMS software, which can then be executed in the browsers of users who visit the affected page. To exploit this, the attacker needs to trick users into clicking a specially crafted link that includes the harmful script.

myadrenalinhuman resource management software
Theoretical
over 7 years agoOct 24, 2018
CVE-2018-122346.1

This vulnerability allows an attacker to inject malicious JavaScript into a webpage, which can then execute in the browser of anyone who visits that page. To exploit this, the attacker needs to trick a user into clicking a link that includes their harmful code in the request to the affected HRMS software.

myadrenalinadrenalin
Exploit Available
over 7 years agoSep 6, 2018
CVE-2018-158996.1

This vulnerability allows an attacker to inject malicious scripts into the MiniCMS website, which can then be executed in the browsers of users visiting the site. It occurs when the website improperly handles input in the "date" parameter of a specific page, meaning an attacker needs to trick users into visiting a specially crafted link to exploit it.

1234nminicms
Exploit Available
over 7 years agoAug 27, 2018
CVE-2017-65416.1

An attacker can inject and run malicious scripts in a user's browser when they visit a specific page on the webpagetest site, potentially stealing sensitive information or manipulating the user's session. This occurs because the site does not properly filter user input, allowing harmful code to be executed if a user is tricked into clicking a specially crafted link.

webpagetest projectwebpagetest
Exploit Available
about 9 years agoMar 8, 2017
CVE-2017-65376.1

An attacker can inject and run malicious scripts in a user's browser when they visit a specific page on a vulnerable webpagetest site. This happens because the site doesn't properly filter user input for a color setting, allowing the attacker to manipulate the page's content if they can trick someone into visiting a crafted link.

webpagetest projectwebpagetest
Exploit Available
about 9 years agoMar 8, 2017
CVE-2017-64786.1

This vulnerability allows an attacker to inject malicious scripts into a web page, which could then be executed in the browser of anyone visiting the affected site. It occurs when a user accesses the installation page with a specially crafted URL, making it possible for the attacker to manipulate the content displayed to users.

mangoswebv4 projectmangoswebv4
Exploit Available
about 9 years agoMar 5, 2017
CVE-2012-64304.3

This vulnerability allows attackers to inject malicious scripts into the admin page of Quick.Cms and Quick.Cart, potentially compromising the site and its users. It affects versions downloaded before December 19, 2012, and requires the attacker to manipulate the URL to exploit the flaw.

opensolutionquick.cart
Exploit Available
about 12 years agoMar 24, 2014
Showing 101 to 110 of 110 results