Search Results (43477 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-29259 1 Online Examination System Project 1 Online Examination System 2024-11-21 5.4 Medium
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the subject or feedback parameter to feedback.php.
CVE-2020-29258 1 Online Examination System Project 1 Online Examination System 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the w parameter to index.php.
CVE-2020-29257 1 Online Examination System Project 1 Online Examination System 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the q parameter to feedback.php.
CVE-2020-29250 1 Cxuu 1 Cxuucms 2024-11-21 6.1 Medium
CXUUCMS V3 allows XSS via the first and third input fields to /public/admin.php.
CVE-2020-29249 1 Cxuu 1 Cxuucms 2024-11-21 6.1 Medium
CXUUCMS V3 allows class="layui-input" XSS.
CVE-2020-29247 1 Wondercms 1 Wondercms 2024-11-21 4.8 Medium
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Admin Panel. An attacker can inject the XSS payload in Page keywords and each time any user will visit the website, the XSS triggers, and the attacker can able to steal the cookie according to the crafted payload.
CVE-2020-29241 1 Online News Portal Project 1 Online News Portal 2024-11-21 4.8 Medium
Online News Portal using PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an arbitrary web script or HTML via the "Title" parameter.
CVE-2020-29240 1 Lepton-cms 1 Leptoncms 2024-11-21 4.8 Medium
Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview section, the XSS will be triggered.
CVE-2020-29239 1 Janobe 1 Online Voting System 2024-11-21 6.1 Medium
Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS). This vulnerability can result in an attacker injecting the XSS payload in the User Registration section. When an admin visits the View Detail of Application section from the admin panel, the attacker can able to steal the cookie according to the crafted payload.
CVE-2020-29233 1 Wondercms 1 Wondercms 2024-11-21 5.4 Medium
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allow an attacker to inject the XSS payload in the Page description and each time any user will visits the website, the XSS triggers and attacker can steal the cookie according to the crafted payload.
CVE-2020-29231 1 Egavilanmedia 1 User Registration And Login System With Admin Panel 2024-11-21 5.4 Medium
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin Full Name and each time admin visits the Profile page from the admin panel, the XSS triggers.
CVE-2020-29230 1 Egavilanmedia 1 User Registration And Login System With Admin Panel 2024-11-21 6.1 Medium
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user. This vulnerability can result in the attacker injecting the XSS payload in the User Registration section and each time admin visits the manage user section from the admin panel, the XSS triggers and the attacker can steal the cookie according to the crafted payload.
CVE-2020-29215 1 Razormist 1 Employee Management System 2024-11-21 5.4 Medium
A Cross Site Scripting in SourceCodester Employee Management System 1.0 allows the user to execute alert messages via /Employee Management System/addemp.php on admin account.
CVE-2020-29205 1 Projectworlds 1 Travel Management System 2024-11-21 6.1 Medium
XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field
CVE-2020-29204 1 Xuxueli 1 Xxl-job 2024-11-21 6.1 Medium
XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.
CVE-2020-29193 1 Panasonic 2 Wv-s2231l, Wv-s2231l Firmware 2024-11-21 6.8 Medium
Panasonic Security System WV-S2231L 4.25 has an insecure hard-coded password of lkjhgfdsa (which is just the asdf keyboard row in reverse order).
CVE-2020-29172 1 Litespeedtech 1 Litespeed Cache 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.
CVE-2020-29171 1 Tipsandtricks-hq 1 Wp Security \& Firewall 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in admin/wp-security-blacklist-menu.php in the Tips and Tricks HQ All In One WP Security & Firewall (all-in-one-wp-security-and-firewall) plugin before 4.4.6 for WordPress.
CVE-2020-29164 1 Rainbowfishsoftware 1 Pacsone Server 2024-11-21 6.1 Medium
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS).
CVE-2020-29146 1 Wayang-cms Project 1 Wayang-cms 2024-11-21 6.1 Medium
A cross site scripting (XSS) vulnerability in index.php of Wayang-CMS v1.0 allows attackers to execute arbitrary web scripts or HTML via a constructed payload created by adding the X-Forwarded-For field to the header.