CWE-79
46,984 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,984)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Arsham Mirshah Add Posts to Pages plugin <= 1.4.1 versions. |
1Catalystconnect 1Catalyst Connect Zoho Crm Client Portal Jun 17, 2026 Aug 10, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Catalyst Connect Catalyst Connect Zoho CRM Client Portal plugin <= 2.0.0 versions. |
An issue was discovered in LWsystems Benno MailArchiv 2.10.1. Attackers can cause XSS via JavaScript content to a mailbox. |
/ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php. |
The Crash Reporter (crash_reporter.php) component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 mishandles input sanitization. |
A cross-site scripting (XSS) vulnerability in the act parameter of system_certmanager.php in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary web scripts or...Show more |
A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to inject arbitrary JavaScript...Show more |
An authenticated attacker with administrative access to the web management interface can inject malicious JavaScript code inside the definition of a Threat Intelligence rule, that will be stored and can later be executed...Show more |
Alteryx Server 2022.1.1.42590 does not employ file type verification for uploaded files. This vulnerability allows attackers to upload arbitrary files (e.g., JavaScript content for stored XSS) via the type field in a JSO...Show more |
social-media-skeleton is an uncompleted social media project implemented using PHP, MySQL, CSS, JavaScript, and HTML. Versions 1.0.0 until 1.0.3 have a stored cross-site scripting vulnerability. The problem is patched in...Show more |
1Microsoft 2Azure Hdinsight Azure HdinsightsAug 10, 2026 Aug 8, 2023 N/A· v4 4.5 MEDIUM· v3 N/A· v2 Azure Apache Hadoop Spoofing Vulnerability |
Microsoft SharePoint Server Spoofing Vulnerability |
Microsoft SharePoint Server Spoofing Vulnerability |
1Microsoft 2Azure Hdinsight Azure HdinsightsAug 10, 2026 Aug 8, 2023 N/A· v4 4.5 MEDIUM· v3 N/A· v2 Azure Apache Ambari Spoofing Vulnerability |
1Microsoft 2Azure Hdinsight Azure HdinsightsAug 10, 2026 Aug 8, 2023 N/A· v4 4.5 MEDIUM· v3 N/A· v2 Azure Apache Oozie Spoofing Vulnerability |
Azure DevOps Server Spoofing Vulnerability |
1Microsoft 2Azure Hdinsight Azure HdinsightsAug 10, 2026 Aug 8, 2023 N/A· v4 4.6 MEDIUM· v3 N/A· v2 Azure HDInsight Jupyter Notebook Spoofing Vulnerability |
1Microsoft 2Azure Hdinsight Azure HdinsightsAug 10, 2026 Aug 8, 2023 N/A· v4 4.5 MEDIUM· v3 N/A· v2 Azure Apache Hive Spoofing Vulnerability |
Cross Site Scripting (XSS) vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted payload to the PersonView.php component. |
Cross Site Scripting (XSS) vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted payload to the systemSettings.php component. |