CWE-79
46,574 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,574)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A stored cross site scripting vulnerabilities exists in DevikaAI from commit 6acce21fb08c3d1123ef05df6a33912bf0ee77c2 onwards via improperly decoded user input. |
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts i...Show more |
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an admin attacker to inject and execute arbi...Show more |
The Sheet to Table Live Sync for Google Sheet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STWT_Sheet_Table shortcode in all versions up to, and including, 1.0.1 due to insufficient...Show more |
The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion block in all versions up to, and including, 2.2.87 due to insufficient input s...Show more |
1Oretnom23 1Clinic's Patient Management System Jun 17, 2026 Aug 14, 2024 5.3 MEDIUM· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /update_medicine.php. The manipulation of the argument me...Show more |
1Remyandrade 1Accounts Manager App Jun 17, 2026 Aug 13, 2024 5.3 MEDIUM· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability, which was classified as problematic, was found in SourceCodester Accounts Manager App 1.0. Affected is an unknown function of the file /endpoint/add-account.php. The manipulation of the argument account_...Show more |
A vulnerability, which was classified as problematic, was found in yzane vscode-markdown-pdf 1.5.0. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remo...Show more |
A vulnerability, which was classified as problematic, was found in FastCMS up to 0.1.5. Affected is an unknown function of the component New Article Category Page. The manipulation leads to cross site scripting. It is po...Show more |
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
Azure Stack Hub Spoofing Vulnerability |
symphonycms <=2.7.10 is vulnerable to Cross Site Scripting (XSS) in the Comment component for articles. |
A Cross Site Scripting (XSS) vulnerability in Symphony CMS 2.7.10 allows remote attackers to inject arbitrary web script or HTML by editing note. |
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Co...Show more |
1Pepperl Fuchs 8Eip/modbus Firmware Ethernet/ip FirmwareIcdm Rx/tcp Socketserver Firmware+5 moreJun 17, 2026 Aug 13, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once. |
1Pepperl Fuchs 8Eip/modbus Firmware Ethernet/ip FirmwareIcdm Rx/tcp Socketserver Firmware+5 moreJun 17, 2026 Aug 13, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once. |
1Pepperl Fuchs 8Eip/modbus Firmware Ethernet/ip FirmwareIcdm Rx/tcp Socketserver Firmware+5 moreJun 17, 2026 Aug 13, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device. |
IBM Common Licensing 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lea...Show more |
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho Campaigns allows Cross-Site Scripting (XSS).This issue affects Zoho Campaigns: from n/a through 2.0.8. |
Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Muhammad Rehman Contact Form 7 Summary and Print allows Stored XSS.This issu...Show more |