CWE-79
47,050 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,050)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Jumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of user input, which can execute any javascript under admin's permission. |
1Cc Custom Taxonomy Project 1Cc Custom Taxonomy Jun 17, 2026 May 24, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in chuyencode CC Custom Taxonomy plugin <= 1.0.1 versions. |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 May 24, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote attackers to inject arbitrary web script or...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 May 24, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Cross-site scripting (XSS) vulnerability in the Account module in Liferay Portal 7.4.3.21 through 7.4.3.62, and Liferay DXP 7.4 update 21 through 62 allows remote attackers to inject arbitrary web script or HTML via a cr...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 May 24, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal 7.4.3.50, and Liferay DXP 7.4 update 50 allows remote attackers to inject arbitrary web script or HT...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 May 24, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.52, and Liferay DXP 7.4 update 41 through 52 allow...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 May 24, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31 allows remote attackers to inject arbitrary web script or HTML via the Re...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 May 24, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Cross-site scripting (XSS) vulnerability in the Modified Facet widget in Liferay Portal 7.1.0 through 7.4.3.12, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 18, 7.3 before update 4, and 7.4 before update 9...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 May 24, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before update 14 allows remote attackers to inject arbitrary web...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 May 24, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and Liferay DXP 7.1 before fix pack 18, and 7.2 before fix pack 5 allows remote attackers to inject arbi...Show more |
1Online Jewelry Store Project 1Online Jewelry Store Jun 17, 2026 May 24, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in SourceCodester Online Jewelry Store 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file customer.php of the component POST Parameter Handler. T...Show more |
A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cros...Show more |
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.19 due to insufficient input sanitization and ou...Show more |
Wuzhi CMS v3.1.2 has a storage type XSS vulnerability in the backend of the Five Finger CMS b2b system. |
Cross-Site Scripting (XSS) vulnerabilities exist in ServiceNow records allowing an authenticated attacker to inject arbitrary scripts. |
1Easyimages2.0 Project 1Easyimages2.0 Jun 17, 2026 May 23, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 EasyImages2.0 ≤ 2.8.1 is vulnerable to Cross Site Scripting (XSS) via viewlog.php. |
Cross-site Scripting vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component) allows Reflected XSS.This issue affects Hitachi Ops Center Analyzer: from 10.9.1-00 before 10.9.2-00....Show more |
1Vektor Inc 1Vk All In One Expansion Unit Jun 17, 2026 May 23, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Cross-site scripting vulnerability in CTA post function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script. |
1Vektor Inc 1Vk All In One Expansion Unit Jun 17, 2026 May 23, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Cross-site scripting vulnerability in Profile setting function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script. |
Cross-site scripting vulnerability in Post function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script. |