← Back
CWE-79

46,989 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,989)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Verint
1Engagement Management
Jun 17, 2026
Aug 2, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Verint Engagement Management 15.3 Update 2023R2 is vulnerable to HTML injection via the user data form in the live chat.
1Mi
1Xiaomi Cloud
Jun 17, 2026
Aug 2, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers...Show more
A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account's cookies.Show less
1Open Xchange
1Open Xchange Appsuite Frontend
Jun 17, 2026
Aug 2, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering...Show more
The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We are now defining the accepted media-type to avoid code execution. No publicly available exploits are known. Show less
1Open Xchange
1Open Xchange Appsuite Frontend
Jun 17, 2026
Aug 2, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering u...Show more
The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We are now defining the accepted media-type to avoid code execution. No publicly available exploits are known. Show less
1Open Xchange
1Open Xchange Appsuite Frontend
Jun 17, 2026
Aug 2, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can be executed within the victims context. This can lead to session hijack...Show more
Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We now sanitize jslob content for those locations to avoid redirects to malicious content. No publicly available exploits are known. Show less
1Open Xchange
1Open Xchange Appsuite Frontend
Jun 17, 2026
Aug 2, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not get escaped before being added to DOM. Malicious script code can be executed withi...Show more
The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not get escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We now sanitize jslob content. No publicly available exploits are known. Show less
1Open Xchange
1Open Xchange Appsuite Frontend
Jun 17, 2026
Aug 2, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unw...Show more
The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We now sanitize the user-controllable clientID parameter. No publicly available exploits are known. Show less
1Open Xchange
1Open Xchange Appsuite Frontend
Jun 17, 2026
Aug 2, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. Malicious script code can be executed within the victims context. This can lead t...Show more
Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web interface and API. To exploit this an attacker would require temporary access to the users account or lure a user to a compromised account. We now sanitize the theme value and use a default fallback if no theme matches. No publicly available exploits are known. Show less
1Mage People
1Bus Ticket Booking With Seat Reservation
Jun 17, 2026
Aug 2, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_date' and 'tab_date_r' parameters in versions up to, and including, 5.2.3 due to insufficient...Show more
The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_date' and 'tab_date_r' parameters in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Aug 2, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was poss...Show more
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A reflected XSS was possible when creating specific PlantUML diagrams that allowed the attacker to perform arbitrary actions on behalf of victims.Show less
1E107
1E107
Jun 17, 2026
Aug 2, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the description function in the SEO project.
1Broadcom
1Brocade Fabric Operating System
Jun 17, 2026
Aug 2, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected cross-site scripting (XSS) vulnerability exists in Brocade Webtools PortSetting.html of Brocade Fabric OS version before Brocade Fabric OS v9.2.0 that could allow a remote unauthenticated attacker to execute...Show more
A reflected cross-site scripting (XSS) vulnerability exists in Brocade Webtools PortSetting.html of Brocade Fabric OS version before Brocade Fabric OS v9.2.0 that could allow a remote unauthenticated attacker to execute arbitrary JavaScript code in a target user’s session with the Brocade Webtools application.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Aug 2, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacke...Show more
An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.Show less
1Faculty Evaluation System Project
1Faculty Evaluation System
Jun 17, 2026
Aug 1, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in Faculty Evaulation System using PHP/MySQLi v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the page parameter.
1Phpjabbers
1Catering System
Jun 17, 2026
Aug 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
PHPJabbers Catering System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /index.php?controller=pjAdmin&action=pjActionForgot.
1Phpjabbers
1Time Slots Booking Calendar
Jun 17, 2026
Aug 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.
1Phpjabbers
1Time Slots Booking Calendar
Jun 17, 2026
Aug 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
There is a Cross Site Scripting (XSS) vulnerability in "cid" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.
1Cubiclesoft
1Barebones Cms
Jun 17, 2026
Aug 1, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Barebones CMS v2.0.2 is vulnerable to Stored Cross-Site Scripting (XSS) when an authenticated user interacts with certain features on the admin panel.
1Checkmk
1Checkmk
Jun 17, 2026
Aug 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30.
1Hcltech
1Verse
Jun 17, 2026
Aug 1, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session to...Show more
HCL Verse is susceptible to a Stored Cross Site Scripting (XSS) vulnerability. An attacker could execute script in a victim's web browser to perform operations as the victim and/or steal the victim's cookies, session tokens, or other sensitive information. Show less