CWE-79
47,136 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,136)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
1Microsoft 1Send Customer Voice Survey From Dynamics 365 Jun 17, 2026 Apr 11, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability |
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
1Oretnom23 1Online Computer And Laptop Store Jun 17, 2026 Apr 11, 2023 N/A· v4 4.8 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/?page=maintenance/brand. The manipul...Show more |
An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface 7.0.0 through 7.0.3, 6.3.0 through 6.3.21, 6.4 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions m...Show more |
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC version 7.1.1 and below, version 7.0.3 and below, version 6.2.5 and below may allow an authentica...Show more |
An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9, version 6.4.0 through 6.4.11 an...Show more |
An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthen...Show more |
1Hitachivantara 1Pentaho Business Analytics Jun 17, 2026 Apr 11, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.3.0.0, 9.2.0.4 and 8.3.0.27 allow a malicious URL to inject content into a dashboard when the CDE plugin is present.
|
A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the state parameter at opencats/index.php?m=candidates. |
A stored cross-site scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the city parameter at opencats/index.php?m=candidates. |
Snippet-box 1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote attackers can render arbitrary web script or HTML from the "Snippet code" form field. |
1Buffalo 7Bs Gs2008 Firmware Bs Gs2008p FirmwareBs Gs2016 Firmware+4 moreJun 17, 2026 Apr 11, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Stored-cross-site scripting vulnerability in Buffalo network devices allows an attacker with access to the web management console of the product to execute arbitrary JavaScript on a legitimate user's web browser. The aff...Show more |
1Epson 50Esifnw1 Firmware Esnsb1 FirmwareEsnsb2 Firmware+47 moreJun 17, 2026 Apr 11, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the soft...Show more |
The SAP Application Interface (Message Monitoring) - versions 600, 700, allows an authorized attacker to input links or headings with custom CSS classes into a comment. The comment will render links and custom CSS classe...Show more |
1Sap 4Abap Platform Application Interface FrameworkBasis+1 moreJun 17, 2026 Apr 11, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The SAP Application Interface (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE 100, 101, SAP_BASIS 755, 756, SAP_ABA 75C, 75D, 75E, application allows the usage HTML tags. An authorized attacker can use some of t...Show more |
1Sap 2Netweaver Netweaver Application Server AbapJun 17, 2026 Apr 11, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 SAP GUI for HTML - versions KERNEL 7.22, 7.53, 7.54, 7.77, 7.81, 7.85, 7.89, 7.91, KRNL64UC, 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT does not sufficiently encode user-controlled inputs, resulting in a reflected Cross-Site...Show more |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Apr 11, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page. |
LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /system/sshkeys.js. |
A cross-site scripting (XSS) vulnerability in LiveAction LiveSP v21.1.2 allows attackers to execute arbitrary web scripts or HTML. |