← Back
CWE-79

47,142 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,142)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Answer
1Answer
Jun 17, 2026
Mar 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
1Answer
1Answer
Jun 17, 2026
Mar 7, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
1Answer
1Answer
Jun 17, 2026
Mar 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
1Answer
1Answer
Jun 17, 2026
Mar 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
1Answer
1Answer
Jun 17, 2026
Mar 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
1Answer
1Answer
Jun 17, 2026
Mar 7, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository answerdev/answer prior to 1.0.6.
1Answer
1Answer
Jun 17, 2026
Mar 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
1Answer
1Answer
Jun 17, 2026
Mar 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.
1Phpipam
1Phpipam
Jun 17, 2026
Mar 7, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository phpipam/phpipam prior to v1.5.2.
1Qlik
1Qlikview
Jul 9, 2026
Mar 6, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functionality.
1Sprymedia
1Datatables
Jun 17, 2026
Mar 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in the DataTables plug-in 1.9.2 for jQuery allows attackers to run arbitrary code via the sBaseName parameter to function _fnCreateCookie. NOTE: 1.9.2 is a version from 2012.
1Moodle
1Moodle
Jun 17, 2026
Mar 6, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk.
1Moodle
1Moodle
Jun 17, 2026
Mar 6, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk.
1Moodle
1Moodle
Jun 17, 2026
Mar 6, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk.
1Sigb
1Pmb
Jun 17, 2026
Mar 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950.php.
1Sigb
1Pmb
Jun 17, 2026
Mar 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950_new.php.
1Woo Popup Project
1Woo Popup
Nov 21, 2024
Mar 6, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability classified as problematic has been found in woo-popup Plugin up to 1.2.2 on WordPress. This affects an unknown part of the file admin/class-woo-popup-admin.php. The manipulation leads to cross site script...Show more
A vulnerability classified as problematic has been found in woo-popup Plugin up to 1.2.2 on WordPress. This affects an unknown part of the file admin/class-woo-popup-admin.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.3.0 is able to address this issue. The patch is named 7c76ac78f3e16015991b612ff4fa616af4ce9292. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-222327.Show less
1Vicidial
1Vicidial
Jul 9, 2026
Mar 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability found in VICIdial v2.14-610c and v.2.10-415c allows attackers execute arbitrary code via the /agc/vicidial.php, agc/vicidial-greay.php, and /vicidial/KHOMP_admin.php parameters.
1Quickentity Editor Project
1Quickentity Editor
Jun 17, 2026
Mar 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
quickentity-editor-next is an open source, system local, video game asset editor. In affected versions HTML tags in entity names are not sanitised (XSS vulnerability). Allows arbitrary code execution within the browser...Show more
quickentity-editor-next is an open source, system local, video game asset editor. In affected versions HTML tags in entity names are not sanitised (XSS vulnerability). Allows arbitrary code execution within the browser sandbox, among other things, simply from loading a file containing a script tag in any entity name. This issue has been patched in version 1.28.1 of the application. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Rangerstudio
1Directus
Jun 17, 2026
Mar 6, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Directus is a real-time API and App dashboard for managing SQL database content. Instances relying on an allow-listed reset URL are vulnerable to an HTML injection attack through the use of query parameters in the reset...Show more
Directus is a real-time API and App dashboard for managing SQL database content. Instances relying on an allow-listed reset URL are vulnerable to an HTML injection attack through the use of query parameters in the reset URL. An attacker could exploit this to email users urls to the servers domain but which may contain malicious code. The problem has been resolved and released under version 9.23.0. People relying on a custom password reset URL should upgrade to 9.23.0 or later, or remove the custom reset url from the configured allow list. Users are advised to upgrade. Users unable to upgrade may disable the custom reset URL allow list as a workaround.Show less