CWE-79
46,808 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,808)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Codeastro 1Restaurant Pos System Jun 17, 2026 Feb 7, 2024 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by this issue is some unknown functionality of the file create_account.php. The manipulation of the ar...Show more |
1Codeastro 1University Management System Jun 17, 2026 Feb 7, 2024 N/A· v4 6.1 MEDIUM· v3 3.3 LOW· v2 A vulnerability classified as problematic was found in CodeAstro University Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /st_reg.php of the component Student Registration...Show more |
1Codeastro 1University Management System Jun 17, 2026 Feb 7, 2024 N/A· v4 4.8 MEDIUM· v3 3.3 LOW· v2 A vulnerability classified as problematic has been found in CodeAstro University Management System 1.0. Affected is an unknown function of the file /att_add.php of the component Attendance Management. The manipulation of...Show more |
A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary...Show more |
An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "dns.0.server" parameter.
|
An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "autorefresh" parameter.
|
An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "username" parameter in the SNMP configuration.
|
An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "forward.0.domain" parameter.
|
1Vmware 1Aria Operations For Networks Jun 17, 2026 Feb 6, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload into the login banner and takeover the user account. |
1Vmware 1Aria Operations For Networks Jun 17, 2026 Feb 6, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user profile configurations due to improper input sanitization...Show more |
A vulnerability was found in Jspxcms 10.2.0. It has been classified as problematic. Affected is an unknown function of the file /ext/collect/find_text.do. The manipulation leads to cross site scripting. It is possible to...Show more |
A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. This issue affects some unknown processing of the file /ext/collect/filter_text.do. The manipulation leads to cross site scripting. The attack ma...Show more |
A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a JavaScript payload when a user views the Debug Samples tab in...Show more |
In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible |
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'reg-number-field...Show more |
1Siteorigin 1Siteorigin Widgets Bundle Jun 17, 2026 Feb 5, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the code editor in all versions up to, and including, 1.58.1 due to insufficient input sanitization and output escaping....Show more |
1Wpdeveloper 1Essential Addons For Elementor Jun 17, 2026 Feb 5, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting through editing context via the 'data-eael-wrapper-lin...Show more |
1Webtechstreet 1Elementor Addon Elements Jun 17, 2026 Feb 5, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_to parameter in all versions up to, and including, 1.12.11 due to insufficient input sanitization and output esc...Show more |
1Devscred 1Exclusive Addons For Elementor Jun 17, 2026 Feb 5, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' url in carousels in all versions up to, and including, 2.6.8 due to insufficient input sanitization a...Show more |
The FileBird plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported folder titles in all versions up to, and including, 5.5.8.1 due to insufficient input sanitization and output escaping. This mak...Show more |