CWE-79
45,650 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (45,650)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con...Show more |
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con...Show more |
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-con...Show more |
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.17.0, an unsanitized JSONP callback parameter allows cross-origin script injection and API key theft....Show more |
1Smoothwall 1Smoothwall Express Jun 17, 2026 Mar 30, 2026 5.1 MEDIUM· v4 6.1 MEDIUM· v3 N/A· v2 Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improper sanitation of the url parameter. Attackers can craft malicious URLs...Show more |
1Smoothwall 1Smoothwall Express Jun 17, 2026 Mar 30, 2026 5.1 MEDIUM· v4 5.4 MEDIUM· v3 N/A· v2 Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPN_IP parameter. Authenticated attackers can in...Show more |
1Ahsanriaz26gmailcom 1Sales And Inventory System Jun 17, 2026 Mar 30, 2026 N/A· v4 9.3 CRITICAL· v3 N/A· v2 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_stock.php file via the "msg" parameter. The application fails to sanit...Show more |
1Ahsanriaz26gmailcom 1Sales And Inventory System Jun 17, 2026 Mar 30, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_purchase.php file via the "msg" parameter. The application fails to sa...Show more |
1Ahsanriaz26gmailcom 1Sales And Inventory System Jun 17, 2026 Mar 30, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_supplier.php file via the "msg" parameter. The application fails to sa...Show more |
1Ahsanriaz26gmailcom 1Sales And Inventory System Jun 17, 2026 Mar 30, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_sales.php file via the "msg" parameter. The application fails to sanit...Show more |
1Ahsanriaz26gmailcom 1Sales And Inventory System Jun 17, 2026 Mar 30, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_customer.php file via the "msg" parameter. The application fails to sa...Show more |
1Ahsanriaz26gmailcom 1Sales And Inventory System Jun 17, 2026 Mar 30, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_category.php file via the "msg" parameter. The application fails to sa...Show more |
1Ahsanriaz26gmailcom 1Sales And Inventory System Jun 17, 2026 Mar 30, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the index.php file via the "msg" parameter. The application fails to sanitize...Show more |
1Ahsanriaz26gmailcom 1Sales And Inventory System Jun 17, 2026 Mar 30, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_customers.php file via the "limit" parameter. The application fails t...Show more |
1Ahsanriaz26gmailcom 1Sales And Inventory System Jun 17, 2026 Mar 30, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_supplier.php file via the "limit" parameter. The application fails to...Show more |
1Ahsanriaz26gmailcom 1Sales And Inventory System Jun 17, 2026 Mar 30, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_payments.php file via the "limit" parameter. The application fails to...Show more |
1Ahsanriaz26gmailcom 1Sales And Inventory System Jun 17, 2026 Mar 30, 2026 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the update_details.php file. The application fails to sanitize the "website" para...Show more |
Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngEstate Server v11.14.0 allow attackers to execute arbitrary web scripts or HTML via injecting a craft...Show more |
1Code Projects 1Exam Form Submission Jun 17, 2026 Mar 30, 2026 1.9 LOW· v4 4.8 MEDIUM· v3 3.3 LOW· v2 A flaw has been found in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file /admin/update_fst.php. Executing a manipulation of the argument sname can lead to cross site script...Show more |
The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter in versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping....Show more |