Description
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) unspecified parameters to apps/calendar/ajax/event/new.php or (2) url parameter to apps/bookmarks/ajax/addBookmark.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Another WordPress Classifieds Arbitrary File Upload (3.3.2)
WordPress 4.9.x Arbitrary File Deletion Vulnerability (4.9 - 4.9.6)
WordPress Plugin Popup Maker-Popup for opt-ins, lead gen, & more Cross-Site Scripting (1.6.4)
AngularJS Improper Input Validation Vulnerability (CVE-2019-10768)