CWE-79
46,909 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,909)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross Site Scripting (XSS) vulnerability in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'error' parameter. |
Cross Site Scripting (XSS) in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'search' parameter in the application URL. |
Cross Site Scripting (XSS) vulnerability in index.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via 'msg' parameter in application URL. |
A vulnerability has been found in Intelbras RX 1500 1.1.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /WiFi.html of the component SSID Handler. The manipulation l...Show more |
DedeCMS v6.2 was discovered to contain a Cross-site Scripting (XSS) vulnerability via spec_add.php. |
An XSS vulnerability has been discovered in ICS Business Manager affecting version 7.06.0028.7066. A remote attacker could send a specially crafted string exploiting the obdd_act parameter, allowing the attacker to steal...Show more |
The POWR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'powr-powr-pack' shortcode in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escapin...Show more |
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and including, 2023.8 due to insufficient input sanitization and output escapin...Show more |
IBM CICS TX Advanced 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential...Show more |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Nov 11, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials di...Show more |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.8, the error message in `WebhookController` returns unescaped user-subm...Show more |
3Debian SensiolabsSymfony4Debian Linux SymfonyTwig+1 moreJul 29, 2026 Nov 10, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExt...Show more |
1Phpgurukul 1Restaurant Table Booking System Jun 17, 2026 Nov 10, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file index.php of the component Reservation Request Handler. The manipula...Show more |
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, some links can inject arbitrary HTML tags wh...Show more |
Cross-site scripting vulnerability in HOTELDRUID 3.0.5 and earlier allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product. |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The course upload preview contained an XSS risk for users uploading unsafe data. |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleJun 17, 2026 Nov 9, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk. |
The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content. |
Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary code via the new component feature in the flexibleLayout plugin. |