← Back
CWE-79

47,050 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,050)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Comment System Project
1Comment System
Jun 17, 2026
May 27, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability classified as problematic has been found in SourceCodester Comment System 1.0. Affected is an unknown function of the file index.php of the component GET Parameter Handler. The manipulation of the argumen...Show more
A vulnerability classified as problematic has been found in SourceCodester Comment System 1.0. Affected is an unknown function of the file index.php of the component GET Parameter Handler. The manipulation of the argument msg leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230076.Show less
1Craftcms
1Craft Cms
Jun 17, 2026
May 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This issue was patched in version 4.4.6.
1Kiwitcms
1Kiwi Tcms
Jun 17, 2026
May 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versions of Kiwi TCMS had introduced upload v...Show more
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versions of Kiwi TCMS had introduced upload validators in order to prevent potentially dangerous files from being uploaded. The upload validation checks were not robust enough which left the possibility of an attacker to circumvent them and upload a potentially dangerous file. Exploiting this flaw, a combination of files could be uploaded so that they work together to circumvent the existing Content-Security-Policy and allow execution of arbitrary JavaScript in the browser. This issue has been patched in version 12.3.Show less
1Posthog
1Posthog Js
Jun 17, 2026
May 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
PostHog-js is a library to interface with the PostHog analytics tool. Versions prior to 1.57.2 have the potential for cross-site scripting. Problem has been patched in 1.57.2. Users are advised to upgrade. Users unable t...Show more
PostHog-js is a library to interface with the PostHog analytics tool. Versions prior to 1.57.2 have the potential for cross-site scripting. Problem has been patched in 1.57.2. Users are advised to upgrade. Users unable to upgrade should ensure that their Content Security Policy is in place.Show less
1Samsung
1Galaxy Store
Jun 17, 2026
May 26, 2023
N/A· v4
9.6 CRITICAL· v3
N/A· v2
XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
1Craftcms
1Craft Cms
Jun 17, 2026
May 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.
2Craftcms
Craftercms
2Craft Cms
Craftercms
Jun 17, 2026
May 26, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in la...Show more
Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was patched in version 4.4.6.Show less
1Uthscsa
1Papaya Viewer
Jun 17, 2026
May 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in Papaya Viewer 1.0.1449. User-supplied input in form of DICOM or NIFTI images can be loaded into the Papaya web application without any kind of sanitization. This allows injection of arbitrary J...Show more
An issue was discovered in Papaya Viewer 1.0.1449. User-supplied input in form of DICOM or NIFTI images can be loaded into the Papaya web application without any kind of sanitization. This allows injection of arbitrary JavaScript code into image metadata, which is executed when that metadata is displayed in the Papaya web application.Show less
1Craftcms
1Craft Cms
Jun 17, 2026
May 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.
1Broadcom
1Vmware Nsx T Data Center
Jun 17, 2026
May 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to redirect to malicious pages.
1Invernyx
1Smartcars 3
Jun 17, 2026
May 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in TFDi Design smartCARS 3 v0.7.0 and below allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the body of news article.
1Craftcms
1Craft Cms
Jun 17, 2026
May 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section...Show more
A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively.Show less
1Skycaiji
1Skycaiji
Jun 17, 2026
May 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
skycaiji v2.5.4 is vulnerable to Cross Site Scripting (XSS). Attackers can achieve backend XSS by deploying malicious JSON data.
1Artistscope
1Copysafe Web Protection
Jun 17, 2026
May 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ArtistScope CopySafe Web Protection plugin <= 3.13 versions.
1Upload File Type Settings Plugin Project
1Upload File Type Settings Plugin
Jun 17, 2026
May 26, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sebastian Krysmanski Upload File Type Settings plugin <= 1.1 versions.
1Squarepiginteractive
1Fusioninvoice
Jun 17, 2026
May 25, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitrary code via the description or content fields to the expenses, tasks, and customer details.
1Dfir Iris
1Iris
Jun 17, 2026
May 25, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. A stored Cross-Site Scripting (XSS) vulnerability has been identified in iris-web, affecting multip...Show more
Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. A stored Cross-Site Scripting (XSS) vulnerability has been identified in iris-web, affecting multiple locations . The vulnerability in allows an attacker to inject malicious scripts into the application, which are then executed when a user visits the affected locations. This can lead to unauthorized access, data theft, or other malicious activities. An attacker need to be authenticated on the application to exploit this vulnerability. The issue was patched in version 2.2.1 of iris-web. Show less
1Mipjz Project
1Mipjz
Jun 17, 2026
May 25, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in mipjz v5.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at /app/tag/controller/ApiAdminTagCategor...Show more
A stored cross-site scripting (XSS) vulnerability in mipjz v5.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at /app/tag/controller/ApiAdminTagCategory.php.Show less
1Mipjz Project
1Mipjz
Jun 17, 2026
May 25, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in mipjz v5.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description parameter at /index.php?s=/article/ApiAdminA...Show more
A stored cross-site scripting (XSS) vulnerability in mipjz v5.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description parameter at /index.php?s=/article/ApiAdminArticle/itemAdd.Show less
1Thecosy
1Icecms
Jun 17, 2026
May 25, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IceCMS v1.0.0 is vulnerable to Cross Site Scripting (XSS).