← Back
CWE-79

47,010 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,010)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Maven Repository Server
Jun 17, 2026
Jun 14, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape project and build display names on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability.
1Jenkins
1Maven Repository Server
Jun 17, 2026
Jun 14, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape the versions of build artifacts on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability expl...Show more
Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape the versions of build artifacts on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control maven project versions in `pom.xml`.Show less
1Online School Fees System Project
1Online School Fees System
Jun 17, 2026
Jun 14, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability, which was classified as problematic, was found in SourceCodester Online School Fees System 1.0. This affects an unknown part of the file /paysystem/branch.php of the component POST Parameter Handler. The...Show more
A vulnerability, which was classified as problematic, was found in SourceCodester Online School Fees System 1.0. This affects an unknown part of the file /paysystem/branch.php of the component POST Parameter Handler. The manipulation of the argument branch leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-231501 was assigned to this vulnerability.Show less
1Microsoft
1Sharepoint Server
Jun 17, 2026
Jun 14, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Microsoft SharePoint Server Spoofing Vulnerability
1Microsoft
1Sharepoint Server
Jun 17, 2026
Jun 14, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Microsoft SharePoint Server Spoofing Vulnerability
1Microsoft
1Azure Devops Server
Jun 17, 2026
Jun 14, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Azure DevOps Server Spoofing Vulnerability
1Microfocus
1Arcsight Logger
Jun 17, 2026
Jun 13, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0
1Digitaldruid
1Hoteldruid
Jun 17, 2026
Jun 13, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick user on browser and/or exfiltrate data.
1Zoom
3Rooms
Virtual Desktop InfrastructureZoom
Jun 17, 2026
Jun 13, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access.
1Zoom
1Zoom
Jun 17, 2026
Jun 13, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victim to a malicious website during meeting creation.
1Zoom
1Zoom
Jun 17, 2026
Jun 13, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim starts a chat with a malicious user it could result in a Zoom application crash.
1Redirect After Login Project
1Redirect After Login
Jun 17, 2026
Jun 13, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcelotorres Redirect After Login plugin <= 0.1.9 versions.
1Mindutopia
1Protected Posts Logout Button
Jun 17, 2026
Jun 13, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nate Reist Protected Posts Logout Button plugin <= 1.4.5 versions.
1Cyberuslabs
1Cyberus Key
Jun 17, 2026
Jun 13, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cyberus Labs Cyberus Key plugin <= 1.0 versions.
1Chat Bee Project
1Chat Bee
Jun 17, 2026
Jun 13, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kamyabsoft Chat Bee plugin <= 1.1.0 versions.
1Shipyaari
1Shipping Management
Jun 17, 2026
Jun 13, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in jinit9906 Shipyaari Shipping Management plugin <= 1.0 versions.
1Designextreme
1We're Open
Jun 17, 2026
Jun 13, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Noah Hearle, Design Extreme We’re Open! plugin <= 1.46 versions.
1Rating Widget
1Ratingwidget
Jun 17, 2026
Jun 13, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Rating-Widget Rating-Widget: Star Review System plugin <= 3.1.9 versions.
1Sap
1Ui
Jun 17, 2026
Jun 13, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not sufficiently encode user-controlled inputs on reading data from the server, resulting in Stored Cross...Show more
SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not sufficiently encode user-controlled inputs on reading data from the server, resulting in Stored Cross-Site Scripting (Stored XSS) vulnerability. After successful exploitation, an attacker with user level access can cause high impact on confidentiality, modify some information and can cause unavailability of the application at user level. Show less
1Sap
1Customer Relationship Management Abap
Jun 17, 2026
Jun 13, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SAP CRM ABAP (Grantor Management) - versions 700, 701, 702, 712, 713, 714, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an att...Show more
SAP CRM ABAP (Grantor Management) - versions 700, 701, 702, 712, 713, 714, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application. Show less