← Back
CWE-79

47,004 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,004)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Simplephpscripts
1Simple Blog
Jun 17, 2026
Jun 30, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability has been found in SimplePHPscripts Simple Blog 3.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file preview.php of the component URL Parameter Handler....Show more
A vulnerability has been found in SimplePHPscripts Simple Blog 3.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. It is recommended to upgrade the affected component. The identifier VDB-232753 was assigned to this vulnerability.Show less
1Pleasanter
1Pleasanter
Jun 17, 2026
Jun 30, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Stored cross-site scripting vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script.
1Sophos
1Web Appliance
Jun 17, 2026
Jun 30, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes.
1Phpmyfaq
1Phpmyfaq
Jun 17, 2026
Jun 30, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta.2.
1Multilaser
1Re170 Firmware
Jul 9, 2026
Jun 30, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Stored Cross-Site Scripting (XSS) vulnerability was found in Multilaser RE 170 using firmware 2.2.6733.
1Simplephpscripts
1Classified Ads Script Php
Jun 17, 2026
Jun 29, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file user.php of the component HTTP POST Req...Show more
A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file user.php of the component HTTP POST Request Handler. The manipulation of the argument title leads to cross site scripting. The attack can be launched remotely. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-232711.Show less
1Simplephpscripts
1Classified Ads Script Php
Jun 17, 2026
Jun 29, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipul...Show more
A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation of the argument p leads to cross site scripting. It is possible to launch the attack remotely. It is recommended to upgrade the affected component. VDB-232710 is the identifier assigned to this vulnerability.Show less
1Xwiki
1Commons
Jun 17, 2026
Jun 29, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML tags. In the context of XWiki, this allows an att...Show more
Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML tags. In the context of XWiki, this allows an attacker without script right to either create forms that can be used for phishing attacks or also in the context of a sheet, the attacker could add an input like `{{html}}<input type="hidden" name="content" value="{{groovy}}println(&quot;Hello from Groovy!&quot;)" />{{/html}}` that would allow remote code execution when it is submitted by an admin (the sheet is rendered as part of the edit form). The attacker would need to ensure that the edit form looks plausible, though, which can be non-trivial as without script right the attacker cannot display the regular content of the document. This has been patched in XWiki 14.10.6 and 15.2RC1 by removing the central form-related tags from the list of allowed tags. Users are advised to upgrade. As a workaround an admin can manually disallow the tags by adding `form, input, select, textarea, button` to the configuration option `xml.htmlElementSanitizer.forbidTags` in the `xwiki.properties` configuration file.Show less
1Ilias
1Ilias
Jun 17, 2026
Jun 29, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to reflected Cross-Site Scripting (XSS).
1Ilias
1Ilias
Jun 17, 2026
Jun 29, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS).
1Mediawiki
1Mediawiki
Jun 17, 2026
Jun 29, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. It allows one to store javascript: URLs in URL fields, and automatically links these URLs.
1Mediawiki
1Mediawiki
Jun 17, 2026
Jun 29, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In Special:CheckUser, a check of the "get edits" type is vulnerable to HTML injection through the User-Agent HTTP request header.
1Mediawiki
1Mediawiki
Jun 17, 2026
Jun 29, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. XSS can occur in Special:CargoQuery via a crafted page item when using the default format.
1Mediawiki
1Mediawiki
Jun 17, 2026
Jun 29, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in the GoogleAnalyticsMetrics extension for MediaWiki through 1.39.3. The googleanalyticstrackurl parser function does not properly escape JavaScript in the onclick handler and does not prevent us...Show more
An issue was discovered in the GoogleAnalyticsMetrics extension for MediaWiki through 1.39.3. The googleanalyticstrackurl parser function does not properly escape JavaScript in the onclick handler and does not prevent use of javascript: URLs.Show less
1Gibbonedu
1Gibbon
Jun 17, 2026
Jun 29, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript code.
1Online Hotel Management System Project
1Online Hotel Management System
Jun 17, 2026
Jun 29, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote code execution can be achieved by entering malicious code in the date selection box.
1Odysseycs
1Ithacalabs Turnitin Lti
Jun 17, 2026
Jun 29, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The "Submission Web Form" of Turnitin LTI tool/plugin version 1.3 is affected by HTML Injection attacks. The security issue affects the submission web form ("id" and "title" HTTP POST parameters) where the students submi...Show more
The "Submission Web Form" of Turnitin LTI tool/plugin version 1.3 is affected by HTML Injection attacks. The security issue affects the submission web form ("id" and "title" HTTP POST parameters) where the students submit their reports for similarity/plagiarism checks.Show less
1Secnet
1Annet Ac Centralized Management Platform
Jun 17, 2026
Jun 29, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Annet AC Centralized Management Platform 1.02.040 is vulnerable to Stored Cross-Site Scripting (XSS) .
1User Registration & Login And User Management System With Admin Panel Project
1User Registration & Login And User Management System With Admin Panel
Jun 17, 2026
Jun 29, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A Cross Site Scripting vulnerability in PHPgurukl User Registration Login and User Management System with admin panel v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the signup.php.
1Churchcrm
1Churchcrm
Jun 17, 2026
Jun 29, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Multiple cross-site scripting (XSS) vulnerabilities were discovered in Church CRM v4.5.3 in GroupReports.php via GroupRole, ReportModel, and OnlyCart parameters.