|
224351
|
6.1 |
MEDIUM
Network
|
cththemes
|
citybook easybook townhub
|
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20212
|
2024-11-21 13:38 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224352
|
6.1 |
MEDIUM
Network
|
cththemes
|
citybook easybook townhub
|
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address,…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20211
|
2024-11-21 13:38 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224353
|
6.1 |
MEDIUM
Network
|
cththemes
|
citybook easybook townhub
|
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20210
|
2024-11-21 13:38 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224354
|
7.5 |
HIGH
Network
|
cththemes
|
citybook easybook townhub
|
The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/p…
|
CWE-79 CWE-639
Cross-site Scripting Authorization Bypass Through User-Controlled Key
|
CVE-2019-20209
|
2024-11-21 13:38 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224355
|
6.1 |
MEDIUM
Network
|
tophub
|
toplist
|
TopList before 2019-09-03 allows XSS via a title.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20377
|
2024-11-21 13:38 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224356
|
6.1 |
MEDIUM
Network
|
ganglia
|
ganglia-web
|
ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php cs parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20379
|
2024-11-21 13:38 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224357
|
6.1 |
MEDIUM
Network
|
ganglia
|
ganglia-web
|
ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php ce parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20378
|
2024-11-21 13:38 |
2020-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224358
|
6.1 |
MEDIUM
Network
|
psi
|
electronic_logbook
|
A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG document to elogd.c.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20376
|
2024-11-21 13:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224359
|
6.1 |
MEDIUM
Network
|
psi
|
electronic_logbook
|
A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrary web script or HTML via the value parameter in a localization (loc) command to…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20375
|
2024-11-21 13:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224360
|
9.6 |
CRITICAL
Network
|
typora
|
typora
|
A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20374
|
2024-11-21 13:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|