CWE-79
46,575 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,575)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Qwik is a performance focused javascript framework. A potential mutation XSS vulnerability exists in Qwik for versions up to but not including 1.6.0. Qwik improperly escapes HTML on server-side rendering. It converts str...Show more |
The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129. |
Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129. |
Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129. |
1Phpgurukul 1Tourism Management System Jun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the una...Show more |
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not properly neutralize input during a web page generation. |
A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware contained multiple XSS vulnerabilities in the version of JavaScript used. |
A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML via the 'keywords' parameter. |
ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injection vulnerability. |
Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker able to inject an HTML...Show more |
1Janobe 1School Event Management System Jun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' pa...Show more |
1Janobe 1School Event Management System Jun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' pa...Show more |
1Janobe 1School Event Management System Jun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the infor...Show more |
1Janobe 1School Event Management System Jun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the infor...Show more |
1Janobe 1School Event Management System Jun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user an...Show more |
1Janobe 1School Event Management System Jun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user an...Show more |
1Janobe 2School Attendence Monitoring System School Event Management SystemJun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain...Show more |
1Janobe 2School Attendence Monitoring System School Event Management SystemJun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain...Show more |
1Janobe 2School Attendence Monitoring System School Event Management SystemJun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain...Show more |
1Janobe 2School Attendence Monitoring System School Event Management SystemJun 17, 2026 Aug 6, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain...Show more |