CWE-79
46,627 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,627)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Mf Gig Calendar Project 1Mf Gig Calendar Jun 17, 2026 May 6, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unf...Show more |
1Crelly Slider Project 1Crelly Slider Jun 17, 2026 May 6, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Crelly Slider WordPress plugin through 1.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilt...Show more |
The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when t...Show more |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 6, 2024 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. Affected by this issue is some unknown functionality of the file /view/teacher_attendance...Show more |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 6, 2024 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/teacher_salary_details.php. T...Show more |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 6, 2024 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/teacher_salary_details2.php. The manipulation of th...Show more |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 6, 2024 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /view/teacher_salary_details3.php. The mani...Show more |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 6, 2024 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /view/teacher_salary_invoice.php. The manip...Show more |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 6, 2024 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /view/teacher_salary_invoice1.php. The manipulation...Show more |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 6, 2024 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /view/timetable.php. The manipulation...Show more |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 6, 2024 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /view/timetable_grade_wise...Show more |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 6, 2024 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/timetable_insert_form.php. The manipulation...Show more |
1Campcodes 1Complete Web Based School Management System Jun 17, 2026 May 6, 2024 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. This issue affects some unknown processing of the file /view/timetable_update_form.php. T...Show more |
1Fast5 1Prison Management System Jun 17, 2026 May 6, 2024 N/A· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0. This vulnerability affects unknown code of the file /Employee/edit-profile.php. The manipulation of the argument txtfull...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 May 5, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not e...Show more |
Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save. |
Rukovoditel before 3.5.3 allows XSS via user_photo to My Page. |
ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl. |
Alinto SOGo through 5.10.0 allows XSS during attachment preview. |
The Tree Explorer tool from Organizer in Zenario before 9.5.60602 is affected by XSS. (This component was removed in 9.5.60602.) |