← Back
CWE-79

46,879 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,879)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phpjabbers
1Appointment Scheduler
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.
1Phpjabbers
1Car Rental Script
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
1Phpjabbers
1Car Rental Script
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
1Phpjabbers
1Time Slots Booking Calendar
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
1Phpjabbers
1Time Slots Booking Calendar
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
1Phpjabbers
1Availability Booking Calendar
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Availability Booking Calendar 5.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
1Boidcms
1Boidcms
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
BoidCMS 2.0.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the title, subtitle, footer, or keywords parameter in a page=create action.
1Phpjabbers
1Availability Booking Calendar
Jun 17, 2026
Dec 7, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index...Show more
A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php.Show less
1Mayurik
1Courier Management System
Jun 17, 2026
Dec 7, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A Cross Site Scripting (XSS) vulnerability in GaatiTrack Courier Management System 1.0 allows a remote attacker to inject JavaScript via the page parameter to login.php or header.php.
1Phpjabbers
1Shuttle Booking Software
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Cross Site Scripting (XSS) vulnerability in Shuttle Booking Software 2.0 allows a remote attacker to inject JavaScript via the name, description, title, or address parameter to index.php.
1Squidex.io
1Squidex
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME element....Show more
Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME element. An authenticated attack with assets.create permission is required for exploitation.Show less
1Zimbra
1Collaboration
Jun 17, 2026
Dec 7, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An XSS issue was discovered in a web endpoint in Zimbra Collaboration (ZCS) before 10.0.4 via an unsanitized parameter. This is also fixed in 8.8.15 Patch 43 and 9.0.0 Patch 36.
1Zimbra
1Collaboration
Jun 17, 2026
Dec 7, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.4. An XSS issue can be exploited to access the mailbox of an authenticated user. This is also fixed in 8.8.15 Patch 43 and 9.0.0 Patch 36.
1Lfprojects
1Mlflow
Jun 17, 2026
Dec 7, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected Cross-Site Scripting (XSS) vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the Content-Type header in POST requests. An attacker can inject malicious JavaScript code...Show more
A reflected Cross-Site Scripting (XSS) vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the Content-Type header in POST requests. An attacker can inject malicious JavaScript code into the Content-Type header, which is then improperly reflected back to the user without adequate sanitization or escaping, leading to arbitrary JavaScript execution in the context of the victim's browser. The vulnerability is present in the mlflow/server/auth/__init__.py file, where the user-supplied Content-Type header is directly injected into a Python formatted string and returned to the user, facilitating the XSS attack.Show less
1Hcltech
1Connections
Jun 17, 2026
Dec 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which lea...Show more
HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user after visiting the vulnerable URL which leads to executing malicious script code. This may let the attacker steal cookie-based authentication credentials and comprise a user's account then launch other attacks. Show less
1Pleasanter
1Pleasanter
Jun 17, 2026
Dec 6, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Pleasanter 1.3.47.0 and earlier contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web browser.
1I13websolution
1Email Subscription Popup
Jun 17, 2026
Dec 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Email Subscription Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP_REFERER header in all versions up to, and including, 1.2.18 due to insufficient input sanitization and output...Show more
The Email Subscription Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP_REFERER header in all versions up to, and including, 1.2.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.Show less
1Daicuo
1Daicuo
Jul 9, 2026
Dec 6, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in /admin.php of DaiCuo v2.5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
1Afian
1Filerun
Jun 17, 2026
Dec 6, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Stored XSS issue in shared files download terms in Filerun Update 20220202 allows attackers to inject JavaScript code that is executed when a user follows the crafted share link.
1Michaelschwarz
1Ajax.net Professional
Jun 17, 2026
Dec 5, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Ajax.NET Professional (AjaxPro) is an AJAX framework for Microsoft ASP.NET which will create proxy JavaScript classes that are used on client-side to invoke methods on the web server. Affected versions of this package ar...Show more
Ajax.NET Professional (AjaxPro) is an AJAX framework for Microsoft ASP.NET which will create proxy JavaScript classes that are used on client-side to invoke methods on the web server. Affected versions of this package are vulnerable cross site scripting attacks. Releases before version 21.12.22.1 are affected. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less