← Back
CWE-79

46,808 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,808)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Dynamics 365
Aug 10, 2026
Feb 13, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
1Microsoft
1Dynamics 365
Aug 10, 2026
Feb 13, 2024
N/A· v4
7.6 HIGH· v3
N/A· v2
Dynamics 365 Field Service Spoofing Vulnerability
1Microsoft
1Dynamics 365
Aug 10, 2026
Feb 13, 2024
N/A· v4
7.6 HIGH· v3
N/A· v2
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
1Microsoft
1Dynamics 365
Aug 10, 2026
Feb 13, 2024
N/A· v4
7.6 HIGH· v3
N/A· v2
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
1Microsoft
1Dynamics 365
Aug 10, 2026
Feb 13, 2024
N/A· v4
7.6 HIGH· v3
N/A· v2
Dynamics 365 Sales Spoofing Vulnerability
1Microsoft
1Dynamics 365
Aug 10, 2026
Feb 13, 2024
N/A· v4
7.6 HIGH· v3
N/A· v2
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
1Microsoft
1Azure Stack Hub
Aug 10, 2026
Feb 13, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Azure Stack Hub Spoofing Vulnerability
1Zimbra
1Collaboration
Jun 17, 2026
Feb 13, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the Modern UI.
1Zimbra
1Collaboration
Jun 17, 2026
Feb 13, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can occur via JavaScript code in a link (for a webmail redirection endpoint) within en email message, e.g...Show more
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. XSS, with resultant session stealing, can occur via JavaScript code in a link (for a webmail redirection endpoint) within en email message, e.g., if a victim clicks on that link within Zimbra webmail.Show less
1Zimbra
1Collaboration
Jun 17, 2026
Feb 13, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. An attacker can send a PDF document through mail that contains malicious JavaScript. While previewing this file in webmail in the Chrome browse...Show more
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. An attacker can send a PDF document through mail that contains malicious JavaScript. While previewing this file in webmail in the Chrome browser, the stored XSS payload is executed. (This has been mitigated by sanitising the JavaScript code present in a PDF document.)Show less
1Zimbra
1Collaboration
Jun 17, 2026
Feb 13, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help document endpoint in webmail, an attacker can inject JavaScript or HTML code that leads to cross-site scripting (XSS). (Adding...Show more
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help document endpoint in webmail, an attacker can inject JavaScript or HTML code that leads to cross-site scripting (XSS). (Adding an adequate message to avoid malicious code will mitigate this issue.)Show less
1Bold Themes
1Bold Page Builder
Jun 17, 2026
Feb 13, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Link in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. T...Show more
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Link in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-30442 is likely a duplicate of this issue.Show less
1Bold Themes
1Bold Page Builder
Jun 17, 2026
Feb 13, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping...Show more
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Bold Themes
1Bold Page Builder
Jun 17, 2026
Feb 13, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button URL in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping....Show more
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button URL in all versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Trellix
1Central Management System
Jun 17, 2026
Feb 13, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary content to be injected into t...Show more
A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary content to be injected into the response when accessing the CM dashboard. Show less
1Sap
1Companion
Jun 17, 2026
Feb 13, 2024
N/A· v4
7.6 HIGH· v3
N/A· v2
SAP Companion - version <3.1.38, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive informa...Show more
SAP Companion - version <3.1.38, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information and cause minor impact on the integrity of the web application. Show less
1Sap
1Crm Webclient Ui
Jun 17, 2026
Feb 13, 2024
N/A· v4
4.1 MEDIUM· v3
N/A· v2
SAP CRM WebClient UI - version S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlle...Show more
SAP CRM WebClient UI - version S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges can cause limited impact to integrity of the application data after successful exploitation. There is no impact on confidentiality and availability. Show less
1Sap
1Crm Webclient Ui
Jun 17, 2026
Feb 13, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, S4FND 108, WEBCUIF 700, WEBCUIF 701, WEBCUIF 730, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 7...Show more
Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, S4FND 108, WEBCUIF 700, WEBCUIF 701, WEBCUIF 730, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability. An attacker with low privileges can cause limited impact to confidentiality and integrity of the appliaction data after successful exploitation. Show less
1Sap
1Netweaver Business Client For Html
Jun 17, 2026
Feb 13, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Script...Show more
SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can inject malicious javascript to cause limited impact to confidentiality and integrity of the application data after successful exploitation.Show less
1Sap
1Netweaver Application Server Java
Jun 17, 2026
Feb 13, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters before including them into the redirect URL. This results in Cross-Site...Show more
The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters before including them into the redirect URL. This results in Cross-Site Scripting (XSS) vulnerability, leading to a high impact on confidentiality and mild impact on integrity and availability.Show less