CWE-79
46,989 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,989)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joseph C Dolson My Content Management plugin <= 1.7.6 versions. |
1Davidlingren 1Media Library Assistant Jun 17, 2026 Aug 5, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in submodule of David Lingren Media Library Assistant plugin <= 3.0.7 versions. |
1Codebard 1Codebard's Patron Button And Widgets For Patreon Jun 17, 2026 Aug 5, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodeBard CodeBard's Patron Button and Widgets for Patreon plugin <= 2.1.8 versions. |
Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1-git. |
A vulnerability was found in DedeBIZ 6.2.10. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Article Handler. The manipulation leads to cross site scripting. The at...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. |
A vulnerability was found in Media Browser Emby Server 4.7.13.0 and classified as problematic. This issue affects some unknown processing of the file /web/. The manipulation leads to cross site scripting. The attack may...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository omeka/omeka-s prior to 4.0.3. |
Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability. |
1Oretnom23 1Lost And Found Information System Jul 9, 2026 Aug 4, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page. |
1Oretnom23 1Toll Tax Management System Jul 9, 2026 Aug 4, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross Site Scripting (XSS) vulnerability in sourcecodester Toll Tax Management System 1.0 allows remote attackers to run arbitrary code via the First Name and Last Name fields on the My Account page. |
1Phpjabbers 1Cleaning Business Software Jun 17, 2026 Aug 4, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 PHPJabbers Cleaning Business Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the theme parameter of preview.php. |
1Phpjabbers 1Class Scheduling System Jun 17, 2026 Aug 4, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduling System 1.0. |
A Persistent XSS vulnerability can be carried out in a certain field of Unica Campaign. An attacker could hijack a user's session and perform other attacks.
|
A Persistent Cross-site Scripting (XSS) vulnerability can be carried out on certain pages of Unica Platform. An attacker could hijack a user's session and perform other attacks.
|
A Persistent Cross-site Scripting (XSS) vulnerability can be carried out in a certain field of the Unica Platform. An attacker could hijack a user's session and perform other attacks.
|
A security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed. This defect was resolved with the release of Foundry Frontend 6.225.0....Show more |
1Cisco 12Spa500ds Firmware Spa500s FirmwareSpa501g Firmware+9 moreJun 17, 2026 Aug 3, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability in web-based management interface of Cisco SPA500 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to to modify a web page in the context of a user's browser. This...Show more |
1Cisco 3Broadworks Application Delivery Platform Broadworks Application ServerBroadworks Xtended Services PlatformJun 17, 2026 Aug 3, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the...Show more |
1Cisco 12Spa500ds Firmware Spa500s FirmwareSpa501g Firmware+9 moreJun 17, 2026 Aug 3, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to conduct XSS attacks. This vulnerability is due to insufficient vali...Show more |