← Back
CWE-79

47,004 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,004)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Escanav
1Escan Management Console
Jun 17, 2026
Jun 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a crafted script to the Dtltyp and ListName parameters.
1Escanav
1Escan Management Console
Jun 17, 2026
Jun 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter.
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Jun 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials d...Show more
IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 248144. Show less
1I Doit
1I Doit
Jun 17, 2026
Jun 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the login page.
1Ibm
1Cloud Pak For Business Automation
Jun 17, 2026
Jun 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre...Show more
IBM Business Automation Workflow is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 255587.Show less
1Dzzoffice
1Dzzoffice
Jun 17, 2026
Jun 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary web scripts or HTML.
1Webcraftplugins
1Image Map Pro
Jun 17, 2026
Jun 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0. This is due to a missing capability check...Show more
The Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.0. This is due to a missing capability check on the ajax_store_save() function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify plugin settings and inject malicious web scripts.Show less
1Trendmicro
1Apex Central
Jun 17, 2026
Jun 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an att...Show more
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authentication to Apex Central on the target system in order to exploit this vulnerability. This is similar to, but not identical to CVE-2023-32604.Show less
1Trendmicro
1Apex Central
Jun 17, 2026
Jun 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an att...Show more
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authentication to Apex Central on the target system in order to exploit this vulnerability. This is similar to, but not identical to CVE-2023-32605.Show less
1Trendmicro
1Apex Central
Jun 17, 2026
Jun 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an att...Show more
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authentication to Apex Central on the target system in order to exploit this vulnerability. This is similar to, but not identical to CVE-2023-32536.Show less
1Trendmicro
1Apex Central
Jun 17, 2026
Jun 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an att...Show more
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authentication to Apex Central on the target system in order to exploit this vulnerability. This is similar to, but not identical to CVE-2023-32537.Show less
1Trendmicro
1Apex Central
Jun 17, 2026
Jun 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar...Show more
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32531 through 32534.Show less
1Trendmicro
1Apex Central
Jun 17, 2026
Jun 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar...Show more
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32531 through 32535.Show less
1Trendmicro
1Apex Central
Jun 17, 2026
Jun 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar...Show more
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32531 through 32535.Show less
1Trendmicro
1Apex Central
Jun 17, 2026
Jun 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar...Show more
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32531 through 32535.Show less
1Trendmicro
1Apex Central
Jun 17, 2026
Jun 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar...Show more
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32532 through 32535.Show less
1Pluck Cms
1Pluck
Jun 17, 2026
Jun 26, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev4 allows remote attackers to run arbitrary code via upload of crafted html file.
1Ibexa
2Ezpublish Legacy
Ezpublish Platform
Jun 17, 2026
Jun 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerabiltiy in eZ Systems AS eZPublish Platform v.5.4 and eZ Publish Legacy v.5.4 allows a remote authenticated attacker to execute arbitrary code via the video-js.swf.
1Tenda
1Ac6 Firmware
Jun 17, 2026
Jun 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Tenda AC6 AC1200 Smart Dual-Band WiFi Router 15.03.06.50_multi was discovered to contain a cross-site scripting (XSS) vulnerability via the deviceId parameter in the Parental Control module.
1Phpgurukul
1Student Study Center Management System
Jun 17, 2026
Jun 26, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" field on Admin Profile page.