cbcvebase.

Microsoft Dynamics 365 vulnerabilities

92 known vulnerabilities affecting microsoft/dynamics_365.

Total CVEs
92
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH24MEDIUM62LOW2

Vulnerabilities

Page 3 of 5
CVE-2020-16878P4MEDIUMCVSS 5.4v8.2v9.02020-09-11
CVE-2020-16878 [MEDIUM] CWE-79 CVE-2020-16878: <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not pr A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected Dynamics server. The attacker who successfully exploited the vu
nvd
CVE-2020-16871P4MEDIUMCVSS 5.4v8.2v9.02020-09-11
CVE-2020-16871 [MEDIUM] CWE-79 CVE-2020-16871: <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not pr A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected Dynamics server. The attacker who successfully exploited the vu
nvd
CVE-2020-16858P4MEDIUMCVSS 5.4v9.02020-09-11
CVE-2020-16858 [MEDIUM] CWE-79 CVE-2020-16858: <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not pr A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected Dynamics server. The attacker who successfully exploited the vu
nvd
CVE-2020-16864P4MEDIUMCVSS 5.4v9.02020-09-11
CVE-2020-16864 [MEDIUM] CWE-79 CVE-2020-16864: <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not pr A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected Dynamics server. The attacker who successfully exploited the vu
nvd
CVE-2020-16861P4MEDIUMCVSS 5.4v8.2v9.02020-09-11
CVE-2020-16861 [MEDIUM] CWE-79 CVE-2020-16861: <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not pr A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected Dynamics server. The attacker who successfully exploited the vu
nvd
CVE-2020-1591P4MEDIUMCVSS 5.4v9.02020-08-17
CVE-2020-1591 [MEDIUM] CWE-79 CVE-2020-1591: A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not prope A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected Dynamics server. The attacker who successfully exploited the vuln
nvd
CVE-2026-33103P4MEDIUMCVSS 5.5≥ 9.0, < 9.1.44.152026-04-14
CVE-2026-33103 [MEDIUM] CWE-284 CVE-2026-33103: Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to dis Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.
nvd
CVE-2023-21807P4MEDIUMCVSS 6.5fixed in 9.0.45.11≥ 9.1, < 9.1.16.202023-02-14
CVE-2023-21807 [MEDIUM] CWE-79 CVE-2023-21807: Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
nvd
CVE-2020-16978P4MEDIUMCVSS 5.4v9.02020-10-16
CVE-2020-16978 [MEDIUM] CWE-79 CVE-2020-16978: <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not pr A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected Dynamics server. The attacker who successfully exploited the vu
nvd
CVE-2020-16956P4MEDIUMCVSS 5.4v8.2v9.02020-10-16
CVE-2020-16956 [MEDIUM] CWE-79 CVE-2020-16956: <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not pr A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected Dynamics server. The attacker who successfully exploited the vu
nvd
CVE-2023-21572P4MEDIUMCVSS 6.5fixed in 9.0.45.11≥ 9.1, < 9.1.16.202023-02-14
CVE-2023-21572 [MEDIUM] CWE-79 CVE-2023-21572: Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
nvd
CVE-2018-8606P4MEDIUMCVSS 5.4≥ 8.0, < 8.2.3.00032018-11-14
CVE-2018-8606 [MEDIUM] CVE-2018-8606: A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8605, CVE-20
nvd
CVE-2018-8605P4MEDIUMCVSS 5.4≥ 8.0, < 8.2.3.00032018-11-14
CVE-2018-8605 [MEDIUM] CWE-79 CVE-2018-8605: A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8606,
nvd
CVE-2018-8607P4MEDIUMCVSS 5.4≥ 8.0, < 8.2.3.00032018-11-14
CVE-2018-8607 [MEDIUM] CVE-2018-8607: A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8605, CVE-20
nvd
CVE-2018-8608P4MEDIUMCVSS 5.4≥ 8.0, < 8.2.3.00032018-11-14
CVE-2018-8608 [MEDIUM] CVE-2018-8608: A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8605, CVE-20
nvd
CVE-2025-49745P4MEDIUMCVSS 5.4≥ 9.1, < 9.1.38.102025-08-12
CVE-2025-49745 [MEDIUM] CWE-79 CVE-2025-49745: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dy Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2021-40457P4MEDIUMCVSS 6.1v9.0v9.12021-10-13
CVE-2021-40457 [MEDIUM] CWE-79 CVE-2021-40457: Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
nvd
CVE-2023-36030P4MEDIUMCVSS 6.1≥ 9.0, < 9.0.51.06≥ 9.1, < 9.1.23.102023-11-14
CVE-2023-36030 [MEDIUM] CWE-79 CVE-2023-36030: Microsoft Dynamics 365 Sales Spoofing Vulnerability Microsoft Dynamics 365 Sales Spoofing Vulnerability
nvd
CVE-2020-0656P4MEDIUMCVSS 5.4v7.02020-01-14
CVE-2020-0656 [MEDIUM] CWE-79 CVE-2020-0656: A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not prope A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'.
nvd
CVE-2019-1375P4MEDIUMCVSS 5.4≥ 9.0, < 9.0.9.42019-10-10
CVE-2019-1375 [MEDIUM] CWE-79 CVE-2019-1375: A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not prope A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'.
nvd
Microsoft Dynamics 365 vulnerabilities | cvebase