CWE-79
47,142 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,142)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6. |
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6. |
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6. |
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6. |
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6. |
Cross-site Scripting (XSS) - Reflected in GitHub repository answerdev/answer prior to 1.0.6. |
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6. |
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6. |
Cross-site Scripting (XSS) - Stored in GitHub repository phpipam/phpipam prior to v1.5.2. |
QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functionality. |
Cross Site Scripting (XSS) vulnerability in the DataTables plug-in 1.9.2 for jQuery allows attackers to run arbitrary code via the sBaseName parameter to function _fnCreateCookie. NOTE: 1.9.2 is a version from 2012. |
In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk. |
In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk. |
In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS risk. |
PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950.php. |
PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950_new.php. |
1Woo Popup Project 1Woo Popup Nov 21, 2024 Mar 6, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability classified as problematic has been found in woo-popup Plugin up to 1.2.2 on WordPress. This affects an unknown part of the file admin/class-woo-popup-admin.php. The manipulation leads to cross site script...Show more |
Cross Site Scripting vulnerability found in VICIdial v2.14-610c and v.2.10-415c allows attackers execute arbitrary code via the /agc/vicidial.php, agc/vicidial-greay.php, and /vicidial/KHOMP_admin.php parameters. |
1Quickentity Editor Project 1Quickentity Editor Jun 17, 2026 Mar 6, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 quickentity-editor-next is an open source, system local, video game asset editor. In affected versions HTML tags in entity names are not sanitised (XSS vulnerability). Allows arbitrary code execution within the browser...Show more |
Directus is a real-time API and App dashboard for managing SQL database content. Instances relying on an allow-listed reset URL are vulnerable to an HTML injection attack through the use of query parameters in the reset...Show more |