← Back
CWE-79

46,879 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,879)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Oscommerce
1Oscommerce
Jun 17, 2026
Dec 8, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in osCommerce 4. It has been classified as problematic. This affects an unknown part of the file /b2b-supermarket/catalog/all-products. The manipulation of the argument keywords with the input %...Show more
A vulnerability was found in osCommerce 4. It has been classified as problematic. This affects an unknown part of the file /b2b-supermarket/catalog/all-products. The manipulation of the argument keywords with the input %27%22%3E%3Cimg%2Fsrc%3D1+onerror%3Dalert%28document.cookie%29%3E leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247245 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Qualys
1Private Cloud Platform
Jun 17, 2026
Dec 8, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access...Show more
A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a user with login access to the application to introduce XSS payload via browser details.  Show less
1Jfinalcms Project
1Jfinalcms
Jun 17, 2026
Dec 8, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the navigation management department.
1Jfinalcms Project
1Jfinalcms
Jun 17, 2026
Dec 8, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department.
1Jfinalcms Project
1Jfinalcms
Jun 17, 2026
Dec 8, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the column management department.
1Iteachyou
1Dreamer Cms
Jun 17, 2026
Dec 8, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Dreamer CMS v4.1.3 was discovered to contain a cross-site scripting (XSS) vulnerability in the article management department.
1Html Js
1Doracms
Jun 17, 2026
Dec 8, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image file to the user avatar.
1Formalms
1Formalms
Jun 17, 2026
Dec 7, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in FormaLMS before 4.0.5 allows attackers to run arbitrary code via title parameters.
1Controlbyweb
3X 301 24i Firmware
X 301 I FirmwareX 332 24i Firmware
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could allow an attacker to inject arbitrary scripts into the endpoint of a web interface that could run malic...Show more
The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could allow an attacker to inject arbitrary scripts into the endpoint of a web interface that could run malicious javascript code during a user's session. Show less
1Netscout
1Ngeniusone
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
NETSCOUT nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting (XSS) vulnerability by an authenticated user.
1Netscout
1Ngeniusone
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 4 of 4).
1Netscout
1Ngeniusone
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 3 of 4).
1Netscout
1Ngeniusone
Jun 17, 2026
Dec 7, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
NetScout nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting vulnerability.
1Netscout
1Ngeniusone
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 2 of 4).
1Netscout
1Ngeniusone
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 1 of 4).
1Dedecms
1Dedecms
Jun 17, 2026
Dec 7, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the v parameter at selectimages.php.
1Dedecms
1Dedecms
Jun 17, 2026
Dec 7, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at selectimages.php.
1Mayurik
1Courier Management System
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in Best Courier Management System v.1.000 allows a remote attacker to execute arbitrary code via a crafted payload to the page parameter in the URL.
1Ruckuswireless
37C110 Firmware
E510 FirmwareH320 Firmware+34 more
Jun 17, 2026
Dec 7, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user w...Show more
A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in the product. As for the affected products/models/versions, see the information provided by the vendor listed under [References] section or the list under [Product Status] section.Show less
1Phpjabbers
1Appointment Scheduler
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.