← Back
CWE-79

46,984 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,984)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webmechanix
1Add Posts To Pages
Jun 17, 2026
Aug 10, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Arsham Mirshah Add Posts to Pages plugin <= 1.4.1 versions.
1Catalystconnect
1Catalyst Connect Zoho Crm Client Portal
Jun 17, 2026
Aug 10, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Catalyst Connect Catalyst Connect Zoho CRM Client Portal plugin <= 2.0.0 versions.
1Lw Systems
1Benno Mailarchiv
Jun 17, 2026
Aug 9, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in LWsystems Benno MailArchiv 2.10.1. Attackers can cause XSS via JavaScript content to a mailbox.
1Opnsense
1Opnsense
Jun 17, 2026
Aug 9, 2023
N/A· v4
9.6 CRITICAL· v3
N/A· v2
/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php.
1Opnsense
1Opnsense
Jun 17, 2026
Aug 9, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles input sanitization.
1Opnsense
1Opnsense
Jun 17, 2026
Aug 9, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or...Show more
A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.Show less
1Opnsense
1Opnsense
Jun 17, 2026
Aug 9, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to inject arbitrary JavaScript...Show more
A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to inject arbitrary JavaScript via the URL path.Show less
1Nozominetworks
2Cmc
Guardian
Jun 17, 2026
Aug 9, 2023
7.3 HIGH· v4
4.8 MEDIUM· v3
N/A· v2
An authenticated attacker with administrative access to the web management interface can inject malicious JavaScript code inside the definition of a Threat Intelligence rule, that will be stored and can later be executed...Show more
An authenticated attacker with administrative access to the web management interface can inject malicious JavaScript code inside the definition of a Threat Intelligence rule, that will be stored and can later be executed by another legitimate user viewing the details of such a rule. Via stored Cross-Site Scripting (XSS), an attacker may be able to perform unauthorized actions on behalf of legitimate users and/or gather sensitive information. JavaScript injection was possible in the contents for Yara rules, while limited HTML injection has been proven for packet and STYX rules.Show less
1Alteryx
1Alteryx Server
Jul 9, 2026
Aug 8, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Alteryx Server 2022.1.1.42590 does not employ file type verification for uploaded files. This vulnerability allows attackers to upload arbitrary files (e.g., JavaScript content for stored XSS) via the type field in a JSO...Show more
Alteryx Server 2022.1.1.42590 does not employ file type verification for uploaded files. This vulnerability allows attackers to upload arbitrary files (e.g., JavaScript content for stored XSS) via the type field in a JSON document within a PUT /gallery/api/media request.Show less
1Fobybus
1Social Media Skeleton
Jun 17, 2026
Aug 8, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
social-media-skeleton is an uncompleted social media project implemented using PHP, MySQL, CSS, JavaScript, and HTML. Versions 1.0.0 until 1.0.3 have a stored cross-site scripting vulnerability. The problem is patched in...Show more
social-media-skeleton is an uncompleted social media project implemented using PHP, MySQL, CSS, JavaScript, and HTML. Versions 1.0.0 until 1.0.3 have a stored cross-site scripting vulnerability. The problem is patched in v1.0.3. Show less
1Microsoft
2Azure Hdinsight
Azure Hdinsights
Aug 10, 2026
Aug 8, 2023
N/A· v4
4.5 MEDIUM· v3
N/A· v2
Azure Apache Hadoop Spoofing Vulnerability
1Microsoft
1Sharepoint Server
Jun 17, 2026
Aug 8, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
Microsoft SharePoint Server Spoofing Vulnerability
1Microsoft
1Sharepoint Server
Jun 17, 2026
Aug 8, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
Microsoft SharePoint Server Spoofing Vulnerability
1Microsoft
2Azure Hdinsight
Azure Hdinsights
Aug 10, 2026
Aug 8, 2023
N/A· v4
4.5 MEDIUM· v3
N/A· v2
Azure Apache Ambari Spoofing Vulnerability
1Microsoft
2Azure Hdinsight
Azure Hdinsights
Aug 10, 2026
Aug 8, 2023
N/A· v4
4.5 MEDIUM· v3
N/A· v2
Azure Apache Oozie Spoofing Vulnerability
1Microsoft
1Azure Devops Server
Aug 10, 2026
Aug 8, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Azure DevOps Server Spoofing Vulnerability
1Microsoft
2Azure Hdinsight
Azure Hdinsights
Aug 10, 2026
Aug 8, 2023
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Azure HDInsight Jupyter Notebook Spoofing Vulnerability
1Microsoft
2Azure Hdinsight
Azure Hdinsights
Aug 10, 2026
Aug 8, 2023
N/A· v4
4.5 MEDIUM· v3
N/A· v2
Azure Apache Hive Spoofing Vulnerability
1Churchcrm
1Churchcrm
Jun 17, 2026
Aug 8, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted payload to the PersonView.php component.
1Churchcrm
1Churchcrm
Jun 17, 2026
Aug 8, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted payload to the systemSettings.php component.