CWE-79
47,142 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,142)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Pluginus 1Wordpress Meta Data And Taxonomies Filter Jun 17, 2026 Mar 22, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Meta Data and Taxonomies Filter WordPress plugin, in versions < 1.3.1, is affected by a reflected cross-site scripting vulnerability in the 'tax_name' parameter of the mdf_get_tax_options_in_widget action, which can...Show more |
2Ckeditor Fedoraproject2Ckeditor FedoraJun 17, 2026 Mar 22, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered affecting Iframe Dialog and Media Embed packages. The vulnerability may trigger a JavaScript...Show more |
Gophish through 0.12.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted landing page. |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Mar 22, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable p...Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Mar 22, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable p...Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Mar 22, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable p...Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Mar 22, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable p...Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Mar 22, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable p...Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Mar 22, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Experience Manager versions 6.5.15.0 (and earlier) are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable p...Show more |
A vulnerability was found in DataGear up to 1.11.1 and classified as problematic. This issue affects some unknown processing of the component Graph Dataset Handler. The manipulation leads to cross site scripting. The att...Show more |
EVOLUCARE ECSIMAGING (aka ECS Imaging) < 6.21.5 is vulnerable to Cross Site Scripting (XSS) via new_movie. php. |
1E Commerce System Project 1E Commerce System Jun 17, 2026 Mar 22, 2023 N/A· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability classified as problematic was found in SourceCodester E-Commerce System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/user/controller.php?action=edit. The manipulation...Show more |
1Oretnom23 1Student Study Center Desk Management System Jun 17, 2026 Mar 22, 2023 N/A· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability classified as problematic has been found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file /admin/reports/index.php of the component GET Parame...Show more |
1Oretnom23 1Student Study Center Desk Management System Jun 17, 2026 Mar 22, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/assign/assign.php. The manipula...Show more |
A vulnerability has been found in DataGear up to 1.11.1 and classified as problematic. This vulnerability affects unknown code of the component Plugin Handler. The manipulation leads to cross site scripting. It is possib...Show more |
A vulnerability was found in FeiFeiCMS 2.7.130201. It has been classified as problematic. This affects an unknown part of the file \Public\system\slide_add.html of the component Extension Tool. The manipulation leads to...Show more |
1Hp 3Integrated Lights Out 4 Integrated Lights Out 5Integrated Lights Out 6Jun 17, 2026 Mar 22, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A remote Cross-site Scripting vulnerability was discovered in HPE Integrated Lights-Out 6 (iLO 6), Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4). HPE has provided software updates to resolve this vu...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Mar 22, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Vulnerabilities within the web-based management interface of ClearPass Policy Manager could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful e...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Mar 22, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Vulnerabilities within the web-based management interface of ClearPass Policy Manager could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful e...Show more |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pacsrapor allows Reflected XSS.
This issue affects Pacsrapor: before 1.22. |