← Back
CWE-79

46,939 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,939)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Concretecms
1Concrete Cms
Jun 17, 2026
Oct 6, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to the SEO - Extra from Page Settings. NOTE: the vendor disputes this because this SEO-...Show more
A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to the SEO - Extra from Page Settings. NOTE: the vendor disputes this because this SEO-related header change can only be made by an admin, and allowing an admin to place JavaScript there is an intentional customization feature.Show less
1Concretecms
1Concrete Cms
Jun 17, 2026
Oct 6, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute arbitrary code via a crafted script to Plural Handle of the Data Objects from Syst...Show more
A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute arbitrary code via a crafted script to Plural Handle of the Data Objects from System & Settings.Show less
1Concretecms
1Concrete Cms
Jun 17, 2026
Oct 6, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of Installation or Settings).
1Concretecms
1Concrete Cms
Jun 17, 2026
Oct 6, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Cross Site Scripting (XSS) vulnerability in Concrete CMS from versions 9.2.0 to 9.2.2 allows an attacker to execute arbitrary code via a crafted script to the Tags from Settings - Tags.
1Concretecms
1Concrete Cms
Jun 17, 2026
Oct 6, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local attacker to execute arbitrary code via a crafted script to the Forms of the...Show more
Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local attacker to execute arbitrary code via a crafted script to the Forms of the Data objects.Show less
1Gdidees
1Gdidees Cms
Jun 17, 2026
Oct 6, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
GDidees CMS 3.0 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to the Page Title.
1Opensolution
1Quick Cms
Jun 17, 2026
Oct 5, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Files - Description parameter in the Pages Menu component.
1Milesight
7Ur32 Firmware
Ur32l FirmwareUr35 Firmware+4 more
Jun 17, 2026
Oct 5, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel.
1Htmlsanitizer Project
1Htmlsanitizer
Jun 17, 2026
Oct 5, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. The vulnerability occurs in configurations where foreign content is allowed, i.e. either `svg` or `m...Show more
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. The vulnerability occurs in configurations where foreign content is allowed, i.e. either `svg` or `math` are in the list of allowed elements. In the case an application sanitizes user input with a vulnerable configuration, an attacker could bypass the sanitization and inject arbitrary HTML, including JavaScript code. Note that in the default configuration the vulnerability is not present. The vulnerability has been fixed in versions 8.0.723 and 8.1.722-beta (preview version).Show less
1Ritecms
1Ritecms
Jun 17, 2026
Oct 4, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a payload crafted in the Home Page fields in the Administration menu.
1Zope
1Zope
Jun 17, 2026
Oct 4, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Zope is an open-source web application server. The title property, available on most Zope objects, can be used to store script code that is executed while viewing the affected object in the Zope Management Interface (ZMI...Show more
Zope is an open-source web application server. The title property, available on most Zope objects, can be used to store script code that is executed while viewing the affected object in the Zope Management Interface (ZMI). All versions of Zope 4 and Zope 5 are affected. Patches will be released with Zope versions 4.8.11 and 5.8.6.Show less
1Small Crm Project
1Small Crm
Jun 17, 2026
Oct 4, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in Small CRM in PHP v.3.0 allows a remote attacker to execute arbitrary code via a crafted payload to the Address parameter.
1Mozilla
1Common Voice
Jun 17, 2026
Oct 4, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Common Voice is the web app for Mozilla Common Voice, a platform for collecting speech donations in order to create public domain datasets for training voice recognition-related tools. Version 1.88.2 is vulnerable to ref...Show more
Common Voice is the web app for Mozilla Common Voice, a platform for collecting speech donations in order to create public domain datasets for training voice recognition-related tools. Version 1.88.2 is vulnerable to reflected Cross-Site Scripting given that user-controlled data flows to a path expression (path of a network request). This issue may lead to reflected Cross-Site Scripting (XSS) in the context of Common Voice’s server origin. As of time of publication, it is unknown whether any patches or workarounds exist.Show less
1Pleasantsolutions
1Pleasant Password Server
Jun 17, 2026
Oct 4, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasant Password Server v7.11.41.0 allows attackers to execute arbitrary web scripts or HTML via a crafte...Show more
A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasant Password Server v7.11.41.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cronString parameter.Show less
1Tcman
1Gim
Jun 17, 2026
Oct 4, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The 'sReferencia', 'sDescripcion', 'txtCodigo' and 'txtDescripcion' parameters, in the frmGestionStock.aspx and frmEditServicio.aspx files in TCMAN GIM v8.0.1, could allow an attacker to perform persistent XSS attacks.
1Hp
1Futuresmart 5
Jun 17, 2026
Oct 4, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Certain HP Enterprise LaserJet and HP LaserJet Managed Printers are potentially vulnerable to denial of service due to WS-Print request and potential injections of Cross Site Scripting via jQuery-UI.
1Redhat
4Ansible Automation Controller
Ansible Automation PlatformAnsible Developer+1 more
Jun 17, 2026
Oct 4, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
1Ibm
1Content Navigator
Jun 17, 2026
Oct 4, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in...Show more
IBM Content Navigator 3.0.11, 3.0.13, and 3.0.14 with IBM Daeja ViewOne Virtual is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 264019.Show less
1Easy Chat Server Project
1Easy Chat Server
Jun 17, 2026
Oct 4, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability stored via /registresult.htm (POST method), in the Icon param...Show more
Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability stored via /registresult.htm (POST method), in the Icon parameter. The XSS is loaded from /users.ghp.Show less
1Easy Chat Server Project
1Easy Chat Server
Jun 17, 2026
Oct 4, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability stored via /body2.ghp (POST method), in the mtowho parameter.