CWE-79
47,004 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,004)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Interactsh is an open-source tool for detecting out-of-band interactions. Domains configured with interactsh server prior to version 1.0.0 were vulnerable to subdomain takeover for a specific subdomain, i.e `app.` Intera...Show more |
1Phpgurukul 1Hostel Management System Jun 17, 2026 Jun 28, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS). |
1Phpgurukul 1Hostel Management System Jun 17, 2026 Jun 28, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course. |
1Hospital Management System Project 1Hospital Management System Jun 17, 2026 Jun 28, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 PHPgurukl Hospital Management System v.1.0 is vulnerable to Cross Site Scripting (XSS). |
PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS). |
Emby Server versions < 4.6.0.50 is vulnerable to Cross Site Scripting (XSS) vulnerability via a crafted GET request to /web. |
1Cisco 61Sf200 24 Firmware Sf200 24fp FirmwareSf200 24p Firmware+58 moreJun 17, 2026 Jun 28, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches co...Show more |
1Cisco 3Secure Email And Web Manager Secure Email GatewayWeb Security ApplianceJun 17, 2026 Jun 28, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure...Show more |
1Cisco 3Secure Email And Web Manager Secure Email GatewayWeb Security ApplianceJun 17, 2026 Jun 28, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote...Show more |
1Cisco 3Secure Email And Web Manager Secure Email GatewayWeb Security ApplianceJun 17, 2026 Jun 28, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository spinacms/spina prior to 2.15.1. |
Reflected XSS affects the ‘mode’ parameter in the /admin functionality of the web application in versions <=2.0.44 |
1Nec 17Aterm Wf300hp Firmware Aterm Wg1400hp FirmwareAterm Wg1800hp2 Firmware+14 moreJun 17, 2026 Jun 28, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Improper Neutralization of Input During Web Page Generation vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N,...Show more |
Stored cross site scripting (XSS) vulnerability in Chaoji CMS v2.18 that allows attackers to execute arbitrary code via /index.php?admin-master-webset. |
An issue was discovered in espcms version P8.18101601. There is a cross site scripting (XSS) vulnerability that allows arbitrary code to be executed via the title parameter. |
1Meldekarten Generator Project 1Meldekarten Generator Jun 17, 2026 Jun 27, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Meldekarten generator is an open source project to create a program, running locally in the browser without the need for an internet-connection, to create, store and print registration cards for volunteers. All text fiel...Show more |
Stored cross site scripting (XSS) vulnerability in /index.php?admin-master-navmenu-add of Chaoji CMS v2.18 that allows attackers to execute arbitrary code. |
A stored cross site scripting (XSS) vulnerability in /index.php?admin-master-article-edit of Chaoji CMS v2.18 that allows attackers to obtain administrator privileges. |
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Description parameter. |
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a vulnerable parameter GrpPath. |