← Back
CWE-79

46,612 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,612)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Labvantage
1Laboratory Information Management System
Jun 17, 2026
Jun 17, 2024
5.3 MEDIUM· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability classified as problematic has been found in LabVantage LIMS 2017. This affects an unknown part of the file /labvantage/rc?command=page&page=SampleHistoricalList&_iframename=list&__crc=crc_1701669816260. T...Show more
A vulnerability classified as problematic has been found in LabVantage LIMS 2017. This affects an unknown part of the file /labvantage/rc?command=page&page=SampleHistoricalList&_iframename=list&__crc=crc_1701669816260. The manipulation of the argument height/width leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-268785 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
-
-
Jun 17, 2026
Jun 17, 2024
N/A· v4
8.3 HIGH· v3
N/A· v2
apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty.
1Ibarn Project
1Ibarn
Jun 17, 2026
Jun 17, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /own.php.
1Zhimengzhel
1Ibarn
Jun 17, 2026
Jun 17, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /index.php.
1Rockoa
1Xinhu
Jun 17, 2026
Jun 17, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /chajian/inputChajian.php. component.
1Rockoa
1Xinhu
Jun 17, 2026
Jun 17, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /kaoqin/tpl_kaoqin_locationchange.html component.
1Rockoa
1Xinhu
Jun 17, 2026
Jun 17, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter at /flow/flow.php.
-
-
Jun 17, 2026
Jun 17, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
PHPVOD v4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /view/admin/view.php.
1Strongshop
1Strongshop
Jun 17, 2026
Jun 17, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
StrongShop v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the spec_group_id parameter at /spec/index.blade.php.
1Checkmk
1Checkmk
Jun 17, 2026
Jun 17, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Stored XSS in inventory tree rendering in Checkmk before 2.3.0p7, 2.2.0p28, 2.1.0p45 and 2.0.0 (EOL)
1Wpxpo
1Postx
Jun 17, 2026
Jun 17, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.1.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which co...Show more
The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.1.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacksShow less
1Ghozylab
1Popup Builder
Jun 17, 2026
Jun 17, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow users such as contributor and above to perform Stored Cross-Site Scripting attacks.
1Progress
1Sitefinity
Jun 17, 2026
Jun 16, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.
1Expressionengine
1Expressionengine
Jun 17, 2026
Jun 16, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
ExpressionEngine before 7.4.11 allows XSS.
1Vantiva
1Mediaaccess Dga2232 Firmware
Jun 17, 2026
Jun 16, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Vantiva - MediaAccess DGA2232 v19.4 - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Zkteco
1Zkbiosecurity V5000
Jun 17, 2026
Jun 15, 2024
2.0 LOW· v4
3.5 LOW· v3
4.0 MEDIUM· v2
A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Summer Schedule Handler. The manipulation of the a...Show more
A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Summer Schedule Handler. The manipulation of the argument Schedule Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor explains, "that ZKBio Security V5000 has been withdrawn from the market and [is] recommended for upgrading to the ZKBio CVSecurity latest version." This vulnerability only affects products that are no longer supported by the maintainer.Show less
1Zkteco
1Zkbiosecurity V5000
Jun 17, 2026
Jun 15, 2024
2.0 LOW· v4
3.5 LOW· v3
4.0 MEDIUM· v2
A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Department Section. The manipulation of t...Show more
A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Department Section. The manipulation of the argument Department Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor explains, "that ZKBio Security V5000 has been withdrawn from the market and [is] recommended for upgrading to the ZKBio CVSecurity latest version." This vulnerability only affects products that are no longer supported by the maintainer.Show less
-
-
Jun 17, 2026
Jun 15, 2024
N/A· v4
6.4 MEDIUM· v3
N/A· v2
The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘label_years’ attribute within the Countdown widget in all versions up to, and including, 1.4.1 due to insufficien...Show more
The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘label_years’ attribute within the Countdown widget in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
-
-
Jun 17, 2026
Jun 15, 2024
N/A· v4
6.4 MEDIUM· v3
N/A· v2
The Collapse-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'expand' and 'expandsub' shortcode in all versions up to, and including, 1.8.5.7 due to insufficient input sanitizat...Show more
The Collapse-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'expand' and 'expandsub' shortcode in all versions up to, and including, 1.8.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Datenverwurstungszentrale
1Shariff Wrapper
Jun 17, 2026
Jun 15, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.13 due to insufficient input sanitization and output es...Show more
The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortcode in all versions up to, and including, 4.6.13 due to insufficient input sanitization and output escaping on user supplied attributes such as 'borderradius', 'services' and 'timestamp'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less