← Back
CWE-79

47,146 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,146)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zoneminder
1Zoneminder
Jun 17, 2026
Feb 25, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 are vulnerable to Cross-site Scripting. Log entries can be i...Show more
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 are vulnerable to Cross-site Scripting. Log entries can be injected into the database logs, containing a malicious referrer field. This is unescaped when viewing the logs in the web ui. This issue is patched in version 1.36.33. Show less
1Online Boat Reservation System Project
1Online Boat Reservation System
Jun 17, 2026
Feb 24, 2023
5.1 MEDIUM· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability has been found in SourceCodester/code-projects Online Boat Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /boat/login.php of t...Show more
A vulnerability has been found in SourceCodester/code-projects Online Boat Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /boat/login.php of the component POST Parameter Handler. The manipulation of the argument un leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
11234n
1Minicms
Jun 17, 2026
Feb 24, 2023
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.
1Aioseo
1All In One Seo
Jun 17, 2026
Feb 24, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This m...Show more
The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Contributor+ role to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Aioseo
1All In One Seo
Jun 17, 2026
Feb 24, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This m...Show more
The All in One SEO Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 4.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Administrator role or above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Medical Certificate Generator App Project
1Medical Certificate Generator App
Jun 17, 2026
Feb 24, 2023
N/A· v4
5.4 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been classified as problematic. This affects an unknown part of the component New Record Handler. The manipulation of the argument...Show more
A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been classified as problematic. This affects an unknown part of the component New Record Handler. The manipulation of the argument Firstname/Middlename/Lastname/Suffix/Nationality/Doctor Fullname/Doctor Suffix with the input "><script>prompt(1)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-221739.Show less
1Ss Proj
1Shirasagi
Jun 17, 2026
Feb 24, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Stored cross-site scripting vulnerability in Theme switching function of SHIRASAGI v1.16.2 and earlier versions allows a remote attacker with an administrative privilege to inject an arbitrary script.
1Ss Proj
1Shirasagi
Jun 17, 2026
Feb 24, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Stored cross-site scripting vulnerability in Schedule function of SHIRASAGI v1.16.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script.
1Paypal
1Braintree/sanitize Url
Jun 17, 2026
Feb 24, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
1Business Management System Project
1Business Management System
Jun 17, 2026
Feb 24, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository unilogies/bumsys prior to v2.0.1.
1Squaredup
1Dashboard Server
Jun 17, 2026
Feb 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2).
2Quarkus
Redhat
2Build Of Quarkus
Quarkus
Jun 17, 2026
Feb 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF...Show more
If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature.Show less
1Squaredup
1Dashboard Server
Jun 17, 2026
Feb 23, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 2 of 2).
1Online Pizza Ordering System Project
1Online Pizza Ordering System
Jun 17, 2026
Feb 23, 2023
N/A· v4
5.4 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability classified as problematic was found in SourceCodester Online Pizza Ordering System 1.0. This vulnerability affects unknown code of the file index.php?page=checkout. The manipulation leads to cross site sc...Show more
A vulnerability classified as problematic was found in SourceCodester Online Pizza Ordering System 1.0. This vulnerability affects unknown code of the file index.php?page=checkout. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-221680.Show less
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
1Opennms
2Horizon
Meridian
Jun 17, 2026
Feb 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site scripting in outage/list.htm in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session information. The solution is to upgrade to Meridian 2023.1.0 or newer, or Hor...Show more
Cross-site scripting in outage/list.htm in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session information. The solution is to upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. Show less
1Opennms
2Horizon
Meridian
Jun 17, 2026
Feb 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Reflected cross-site scripting in graph results in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to steal session cookies. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon...Show more
Reflected cross-site scripting in graph results in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to steal session cookies. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. Show less
1Opennms
2Horizon
Meridian
Jun 17, 2026
Feb 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to confidential session information. Users should...Show more
Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to confidential session information. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. Show less
1Open Emr
1Openemr
Jun 17, 2026
Feb 22, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Reflected Cross-site scripting (XSS) vulnerability in interface/forms/eye_mag/php/eye_mag_functions.php in OpenEMR < 7.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the REQUEST_URI.