CWE-79
47,050 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,050)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Tipsandtricks Hq 1Category Specific Rss Feed Subscription Jun 17, 2026 May 12, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tips and Tricks HQ, Ruhul Amin Category Specific RSS feed Subscription plugin <= v2.2 versions. |
Vinteo VCC v2.36.4 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the conference parameter. This vulnerability allows attackers to inject arbitrary code which will be executed by the v...Show more |
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Gautam Thapar Button Builder – Buttons X plugin <= 0.8.6 versions. |
Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary code via the auditlog tab in the admin panel. |
LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack. |
1File Tracker Manager System Project 1File Tracker Manager System Jun 17, 2026 May 12, 2023 N/A· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability has been found in SourceCodester File Tracker Manager System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /file_manager/admin/save_user.php of the component POST...Show more |
1Oretnom23 1Lost And Found Information System Jun 17, 2026 May 12, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file classes/Master.php?f=save_inquiry of the compone...Show more |
1Oretnom23 1Lost And Found Information System Jun 17, 2026 May 12, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability has been found in SourceCodester Lost and Found Information System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/. The manipulation of the...Show more |
IBM Planning Analytics Local 2.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more |
Cross Site Scripting (XSS) vulnerability in vogtmh cmaps (companymaps) 8.0 allows attackers to execute arbitrary code. |
IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more |
A vulnerability has been discovered in Rocket.Chat where a markdown parsing issue in the "Search Messages" feature allows the insertion of malicious tags. This can be exploited on servers with content security policy dis...Show more |
kodbox <= 1.37 is vulnerable to Cross Site Scripting (XSS) via the debug information. |
The MoveIt framework 1.1.11 for ROS allows cross-site scripting (XSS) via the API authentication function. NOTE: this issue is disputed by the original reporter because it has "no impact." |
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareJun 17, 2026 May 11, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User i...Show more |
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareJun 17, 2026 May 11, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User i...Show more |
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareJun 17, 2026 May 11, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify th...Show more |
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareJun 17, 2026 May 11, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify th...Show more |
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareJun 17, 2026 May 11, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify th...Show more |
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareJun 17, 2026 May 11, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify th...Show more |