← Back
CWE-79

47,142 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,142)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Online Pizza Ordering System Project
1Online Pizza Ordering System
Jun 17, 2026
Mar 9, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in /php-opos/login.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter.
2Best Pos Management System Project
Mayurik
2Best Pos Management System
Best Pos Management System
Aug 19, 2026
Mar 9, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in /kruxton/navbar.php of Best POS Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter.
1Pimcore
1Pimcore
Jun 17, 2026
Mar 9, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.19.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 8, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title fie...Show more
A issue has been discovered in GitLab CE/EE affecting all versions from 15.3 prior to 15.7.8, version 15.8 prior to 15.8.4, and version 15.9 prior to 15.9.2 A cross-site scripting vulnerability was found in the title field of work items that allowed attackers to perform arbitrary actions on behalf of victims at client side.Show less
1Wyomind
1Help Desk
Jun 17, 2026
Mar 8, 2023
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field.
1Poly
1Trio 8800 Firmware
Jul 9, 2026
Mar 8, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a crafted ringtone file.
1Ibos
1Ibos
Jun 17, 2026
Mar 8, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability, which was classified as problematic, has been found in IBOS up to 4.5.5. Affected by this issue is some unknown functionality of the file mobil/index.php. The manipulation of the argument accesstoken lea...Show more
A vulnerability, which was classified as problematic, has been found in IBOS up to 4.5.5. Affected by this issue is some unknown functionality of the file mobil/index.php. The manipulation of the argument accesstoken leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-222608.Show less
1Phone Shop Sales Managements System Project
1Phone Shop Sales Managements System
Jun 17, 2026
Mar 8, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability classified as problematic was found in SourceCodester Phone Shop Sales Managements System 1.0. This vulnerability affects unknown code of the file /osms/assets/plugins/jquery-validation-1.11.1/demo/captch...Show more
A vulnerability classified as problematic was found in SourceCodester Phone Shop Sales Managements System 1.0. This vulnerability affects unknown code of the file /osms/assets/plugins/jquery-validation-1.11.1/demo/captcha/index.php of the component CAPTCHA Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-222598 is the identifier assigned to this vulnerability.Show less
1Onekeyadmin
1Onekeyadmin
Jun 17, 2026
Mar 8, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Menu module.
1Btcpayserver
1Btcpayserver
Jun 17, 2026
Mar 8, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting in GitHub repository btcpayserver/btcpayserver prior to 1.8.3.
1Onekeyadmin
1Onekeyadmin
Jun 17, 2026
Mar 8, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Title parameter under the Adding Categories module.
1Phpipam
1Phpipam
Jun 17, 2026
Mar 8, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php.
1Fortinet
1Fortinac
Jun 17, 2026
Mar 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 throu...Show more
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allows attacker to execute unauthorized code or commands via specially crafted http requests.Show less
1Onekeyadmin
1Onekeyadmin
Jun 17, 2026
Mar 7, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Administrator module.
1Health Center Patient Record Management System Project
1Health Center Patient Record Management System
Jun 17, 2026
Mar 7, 2023
N/A· v4
5.4 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability has been found in SourceCodester Health Center Patient Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file birthing_print.php. The manipulation...Show more
A vulnerability has been found in SourceCodester Health Center Patient Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file birthing_print.php. The manipulation of the argument birth_id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222484.Show less
1Ubit
1Student Information Management System
Jun 17, 2026
Mar 7, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technologies Student Information Management System. This issue affects Student Information Management Syste...Show more
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technologies Student Information Management System. This issue affects Student Information Management System: before 20211126.Show less
1Ubit
1Student Information Management System
Jun 17, 2026
Mar 7, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technologies Student Information Management System. This issue affects Student Information Management Syste...Show more
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technologies Student Information Management System. This issue affects Student Information Management System: before 20211126.Show less
1Onekeyadmin Project
1Onekeyadmin
Jun 17, 2026
Mar 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Admin Group module.
1Onekeyadmin Project
1Onekeyadmin
Jun 17, 2026
Mar 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the User Group module.
1Answer
1Answer
Jun 17, 2026
Mar 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.