CWE-79
46,516 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,516)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wpplugin 1Contact Form 7 Redirect & Thank You Page Jun 17, 2026 Nov 12, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization...Show more |
1Leevio 1Happy Addons For Elementor Jun 17, 2026 Nov 12, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to, and including, 3.12.5 due to insuffici...Show more |
Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the login.php component. |
Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute arbitrary Javascript. Exploitation could lead to session hi...Show more |
The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload into the Content= field. |
Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In affected versions the Merge functionality takes untrusted user input (file name) and uses it directly in the...Show more |
Ampache is a web based audio/video streaming application and file manager. This vulnerability exists in the interface section of the Ampache menu, where users can change "Custom URL - Logo". This section is not properly...Show more |
Ampache is a web based audio/video streaming application and file manager. The vulnerability exists in the interface section of the Ampache menu, where users can change the "Custom URL - Favicon". This section is not pro...Show more |
1Trendnet 3Tew 651br Firmware Tew 652brp FirmwareTew 652bru FirmwareJun 17, 2026 Nov 11, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the ptRule_ApplicationName_1.1.6.0.0 parameter on the /special_ap.htm page. |
1Trendnet 3Tew 651br Firmware Tew 652brp FirmwareTew 652bru FirmwareJun 17, 2026 Nov 11, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the macList_Name_1.1.1.0.0 parameter on the /filters.htm page. |
1Trendnet 3Tew 651br Firmware Tew 652brp FirmwareTew 652bru FirmwareJun 17, 2026 Nov 11, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the vsRule_VirtualServerName_1.1.10.0.0 parameter on the /virtual_server.htm page...Show more |
1Trendnet 3Tew 651br Firmware Tew 652brp FirmwareTew 652bru FirmwareJun 17, 2026 Nov 11, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the firewallRule_Name_1.1.1.0.0 parameter on the /firewall_setting.htm page. |
1Anisha 1Job Recruitment Jun 17, 2026 Nov 11, 2024 5.3 MEDIUM· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument e/...Show more |
An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request cont...Show more |
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality po...Show more |
IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality po...Show more |
A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting (XSS) risk. |
1Phpgurukul 1Online Marriage Registration System Jun 17, 2026 Nov 11, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 A Cross Site Scriptng (XSS) vulnerability was found in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System 1.0, which allows remote attackers to execute arbitrary code via the "searchdata" POST reque...Show more |
1Phpgurukul 1User Management System Jun 17, 2026 Nov 11, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 A Cross Site Scripting (XSS) vulnerability was found in /ums-sp/admin/registered-users.php in PHPGurukul User Management System v1.0, which allows remote attackers to execute arbitrary code via the "fname" POST request p...Show more |
1Phpgurukul 1Online Marriage Registration System Jun 17, 2026 Nov 11, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A Reflected Cross Site Scriptng (XSS) vulnerability was found in /omrs/user/search.php in PHPGurukul Online Marriage Registration System v1.0, which allows remote attackers to execute arbitrary code via the "searchdata"...Show more |