← Back
CWE-79

46,944 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,944)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ithewei
1Libhv
Jun 17, 2026
Sep 29, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
All versions of the package ithewei/libhv are vulnerable to HTTP Response Splitting when untrusted user input is used to build headers values. An attacker can add the \r\n (carriage return line feeds) characters to end t...Show more
All versions of the package ithewei/libhv are vulnerable to HTTP Response Splitting when untrusted user input is used to build headers values. An attacker can add the \r\n (carriage return line feeds) characters to end the HTTP response headers and inject malicious content, like for example additional headers or new response body, leading to a potential XSS vulnerability.Show less
1Ithewei
1Libhv
Jun 17, 2026
Sep 29, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
All versions of the package ithewei/libhv are vulnerable to Cross-site Scripting (XSS) such that when a file with a name containing a malicious payload is served by the application, the filename is displayed without prop...Show more
All versions of the package ithewei/libhv are vulnerable to Cross-site Scripting (XSS) such that when a file with a name containing a malicious payload is served by the application, the filename is displayed without proper sanitization when it is rendered.Show less
1Projectworlds
1Online Movie Ticket Booking System
Jun 17, 2026
Sep 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Stored Cross-Site Scripting vulnerability.
1Projectworlds
1Online Movie Ticket Booking System
Jun 17, 2026
Sep 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Reflected Cross-Site Scripting vulnerability.
1Discourse
1Discourse Encrypt
Jun 17, 2026
Sep 28, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
discourse-encrypt is a plugin that provides a secure communication channel through Discourse. Improper escaping of encrypted topic titles could lead to a cross site scripting (XSS) issue when a site has content security...Show more
discourse-encrypt is a plugin that provides a secure communication channel through Discourse. Improper escaping of encrypted topic titles could lead to a cross site scripting (XSS) issue when a site has content security policy (CSP) headers disabled. Having CSP disabled is a non-default configuration, and having it disabled with discourse-encrypt installed will result in a warning in the Discourse admin dashboard. This has been fixed in commit `9c75810af9` which is included in the latest version of the discourse-encrypt plugin. Users are advised to upgrade. Users unable to upgrade should ensure that CSP headers are enabled and properly configured.Show less
1Intelliants
1Subrion
Jun 17, 2026
Sep 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Cross-site scripting (XSS) vulnerability in Reference ID from the panel Transactions, of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Reference ID' param...Show more
A Cross-site scripting (XSS) vulnerability in Reference ID from the panel Transactions, of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Reference ID' parameter.Show less
1Ritecms
1Ritecms
Jun 17, 2026
Sep 28, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the Global Content Blocks in the Administration Menu.
1Ritecms
1Ritecms
Jun 17, 2026
Sep 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload into the Main Menu Items in the Administration Menu.
1Octobercms
1October
Jun 17, 2026
Sep 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost field.
1E107
1E107 Cms
Jun 17, 2026
Sep 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Multiple Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Copyright and Author fields in the Meta & Custom Tags Menu.
1E107
1E107 Cms
Jun 17, 2026
Sep 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Cross Site Scripting (XSS) vulnerability in e017 CMS v.2.3.2 allows a local attacker to execute arbitrary code via a crafted script to the Name filed in the Manage Menu.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Sep 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).
1Wbce
1Wbce Cms
Jun 17, 2026
Sep 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A File upload vulnerability in WBCE v.1.6.1 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).
1Generex
1Cs141 Firmware
Jun 17, 2026
Sep 28, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
There is a file upload XSS vulnerability in Generex CS141 below 2.06 version. The web application allows file uploading, making it possible to upload a file with HTML content. When HTML files are allowed, XSS payload can...Show more
There is a file upload XSS vulnerability in Generex CS141 below 2.06 version. The web application allows file uploading, making it possible to upload a file with HTML content. When HTML files are allowed, XSS payload can be injected into the uploaded file. Show less
1Fontawesome
1Font Awesome Integration
Jun 17, 2026
Sep 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fawesome' shortcode in versions up to, and including, 5.0 due to insufficient input sanitization and output escaping on...Show more
The Font Awesome Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fawesome' shortcode in versions up to, and including, 5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Webguysaz
1Font Awesome More Icons
Jun 17, 2026
Sep 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Font Awesome More Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' shortcode in versions up to, and including, 3.5 due to insufficient input sanitization and output escaping on user...Show more
The Font Awesome More Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' shortcode in versions up to, and including, 3.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Jetimpex
1Tm Woocommerce Compare & Wishlist
Jun 17, 2026
Sep 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The TM WooCommerce Compare & Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tm_woo_wishlist_table' shortcode in versions up to, and including, 1.1.7 due to insufficient input sanitization...Show more
The TM WooCommerce Compare & Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tm_woo_wishlist_table' shortcode in versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Opnsense
1Opnsense
Jun 17, 2026
Sep 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
OPNsense before 23.7.5 allows XSS via the index.php sequence parameter to the Lobby Dashboard.
1Opnsense
1Opnsense
Jun 17, 2026
Sep 28, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
OPNsense before 23.7.5 allows XSS via the index.php column_count parameter to the Lobby Dashboard.
1Quill Mention
1Quill Mention
Jun 17, 2026
Sep 28, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Versions of the package quill-mention before 4.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization, via the renderList function. **Note:** If the mentions list is sourced from unsa...Show more
Versions of the package quill-mention before 4.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization, via the renderList function. **Note:** If the mentions list is sourced from unsafe (user-sourced) data, this might allow an injection attack when a Quill user hits @.Show less