CWE-79
47,123 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,123)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Apr 18, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE endpoint through the logging capabilities of the webserver. Aff...Show more |
1Schneider Electric 1Struxureware Data Center Expert Jun 17, 2026 Apr 18, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists on a DCE file upload endpoint when tampering with parameters over HTTP. Affec...Show more |
1Schneider Electric 5Netbotz 355 Firmware Netbotz 450 FirmwareNetbotz 455 Firmware+2 moreJun 17, 2026 Apr 18, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause code and session manipulation when malicious code is inserted into the browser. Af...Show more |
DirCMS 6.0.0 has a Cross Site Scripting (XSS) vulnerability in the foreground. |
1Air Cargo Management System Project 1Air Cargo Management System Jun 17, 2026 Apr 18, 2023 N/A· v4 4.8 MEDIUM· v3 3.3 LOW· v2 A vulnerability was found in SourceCodester Air Cargo Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file classes/Master.php?f=save_cargo_type. The manipulation...Show more |
Dreamer CMS 3.0.1 is vulnerable to stored Cross Site Scripting (XSS). |
1Complaint Management System Project 1Complaint Management System Jun 17, 2026 Apr 18, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file admin/assets/plugins/DataTables/examples/example...Show more |
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions. |
1Content Repeater Project 1Content Repeater Jun 17, 2026 Apr 18, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Denis Buka Content Repeater – Custom Posts Simplified plugin <= 1.1.13 versions. |
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA WHA Puzzle plugin <= 1.0.9 versions. |
1Reputeinfosystems 1Arforms Form Builder Jun 17, 2026 Apr 18, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARForms Form Builder plugin <= 1.5.5 versions. |
1Wp Clictracker Project 1Wp Clictracker Jun 17, 2026 Apr 18, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gus Sevilla WP Clictracker plugin <= 1.0.5 versions. |
Cross Site Scripting vulnerability found in Jbootfly allows attackers to obtain sensitive information via the username parameter. |
1I13websolution 1Thumbnail Carousel Slider Jun 17, 2026 Apr 18, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Thumbnail carousel slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.1.9 due to insufficient input sanitization and output e...Show more |
1I13websolution 1Responsive Filterable Portfolio Jun 17, 2026 Apr 18, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Responsive Filterable Portfolio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search_term parameter in versions up to, and including, 1.0.19 due to insufficient input sanitization and o...Show more |
There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthent...Show more |
The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users wi...Show more |
The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role...Show more |
1Timesheets For Jira 1Timesheet Tracking Jun 17, 2026 Apr 17, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view. |
Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.14.0. |