← Back
CWE-79

47,123 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,123)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Schneider Electric
1Struxureware Data Center Expert
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE endpoint through the logging capabilities of the webserver. Aff...Show more
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE endpoint through the logging capabilities of the webserver. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior) Show less
1Schneider Electric
1Struxureware Data Center Expert
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE file upload endpoint when tampering with parameters over HTTP. Affec...Show more
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE file upload endpoint when tampering with parameters over HTTP. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior) Show less
1Schneider Electric
5Netbotz 355 Firmware
Netbotz 450 FirmwareNetbotz 455 Firmware+2 more
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause code and session manipulation when malicious code is inserted into the browser. Af...Show more
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause code and session manipulation when malicious code is inserted into the browser. Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0 and prior)Show less
1Dircms Project
1Dircms
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
DirCMS 6.0.0 has a Cross Site Scripting (XSS) vulnerability in the foreground.
1Air Cargo Management System Project
1Air Cargo Management System
Jun 17, 2026
Apr 18, 2023
N/A· v4
4.8 MEDIUM· v3
3.3 LOW· v2
A vulnerability was found in SourceCodester Air Cargo Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file classes/Master.php?f=save_cargo_type. The manipulation...Show more
A vulnerability was found in SourceCodester Air Cargo Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file classes/Master.php?f=save_cargo_type. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226276.Show less
1Iteachyou
1Dreamer Cms
Jun 17, 2026
Apr 18, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Dreamer CMS 3.0.1 is vulnerable to stored Cross Site Scripting (XSS).
1Complaint Management System Project
1Complaint Management System
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file admin/assets/plugins/DataTables/examples/example...Show more
A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file admin/assets/plugins/DataTables/examples/examples_support/editable_ajax.php of the component POST Parameter Handler. The manipulation of the argument value with the input 1><script>alert(666)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-226274 is the identifier assigned to this vulnerability.Show less
1W3eden
1Download Manager
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.
1Content Repeater Project
1Content Repeater
Jun 17, 2026
Apr 18, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Denis Buka Content Repeater – Custom Posts Simplified plugin <= 1.1.13 versions.
1Webhelpagency
1Wha Puzzle
Jun 17, 2026
Apr 18, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA WHA Puzzle plugin <= 1.0.9 versions.
1Reputeinfosystems
1Arforms Form Builder
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARForms Form Builder plugin <= 1.5.5 versions.
1Wp Clictracker Project
1Wp Clictracker
Jun 17, 2026
Apr 18, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gus Sevilla WP Clictracker plugin <= 1.0.5 versions.
1Jbootfly Project
1Jbootfly
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability found in Jbootfly allows attackers to obtain sensitive information via the username parameter.
1I13websolution
1Thumbnail Carousel Slider
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Thumbnail carousel slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.9 due to insufficient input sanitization and output e...Show more
The Thumbnail carousel slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.Show less
1I13websolution
1Responsive Filterable Portfolio
Jun 17, 2026
Apr 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.19 due to insufficient input sanitization and o...Show more
The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.Show less
1Servicenow
1Servicenow
Jun 17, 2026
Apr 17, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthent...Show more
There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthenticated remote attacker to execute arbitrary JavaScript code in the browser-based web console.Show less
1Yikesinc
1Easy Forms For Mailchimp
Jun 17, 2026
Apr 17, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users wi...Show more
The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacksShow less
1W4 Post List Project
1W4 Post List
Jun 17, 2026
Apr 17, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role...Show more
The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.Show less
1Timesheets For Jira
1Timesheet Tracking
Jun 17, 2026
Apr 17, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view.
1Chatwoot
1Chatwoot
Jun 17, 2026
Apr 17, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.14.0.