CWE-79
47,151 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,151)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Azure DevOps Server Cross-Site Scripting Vulnerability |
1Linuxfoundation 3Backstage Catalog Model Backstage Core ComponentsBackstage Plugin Catalog BackendJun 17, 2026 Feb 14, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Backstage is an open platform for building developer portals. `@backstage/catalog-model` prior to version 1.2.0, `@backstage/core-components` prior to 0.12.4, and `@backstage/plugin-catalog-backend` prior to 1.7.2 are af...Show more |
1Splunk 2Splunk Splunk Cloud PlatformJun 17, 2026 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a View allows for Cross-Site Scripting (XSS) in an extensible mark-up language (XML) View through the ‘layoutPanel’ attribute in the ‘module’ tag’. |
1Splunk 2Splunk Splunk Cloud PlatformJun 17, 2026 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 In Splunk Enterprise 9.0 versions before 9.0.4, a View allows for Cross-Site Scripting (XSS) through the error message in a Base64-encoded image. The vulnerability affects instances with Splunk Web enabled. It does not a...Show more |
A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the conte...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 1.5.17. |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 SAP NetWeaver AS ABAP (BSP Framework) application - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allow an unauthenticated attacker to inject the code that can be executed by the application o...Show more |
1Sap 1Netweaver As Abap Business Server Pages Jun 17, 2026 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 75H, allow malicious inputs from untrusted sources, which can be leverag...Show more |
1Sap 2Customer Relationship Management Webclient Ui S4fndJun 17, 2026 Feb 14, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an authenticat...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, allows an unauthenticated user to alter the current session of the user by injecting the malicious...Show more |
1Sap 1Netweaver As Abap Business Server Pages Jun 17, 2026 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Feb 14, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and...Show more |
1Sap 1Business Objects Business Intelligence Platform Jun 17, 2026 Feb 14, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls dir...Show more |
SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
|
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or cr...Show more |
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or cr...Show more |
Reflected cross-site scripting vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a remote unauthenticated attacker to inject arbitrary script to inject an arbitrary script. NOTE: T...Show more |
Stored cross-site scripting vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a network-adjacent authenticated attacker to inject an arbitrary script. NOTE: This vulnerability only...Show more |
1Walrusirc Project 1Walrusirc Nov 21, 2024 Feb 13, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in juju2143 WalrusIRC 0.0.2. It has been rated as problematic. This issue affects the function parseLinks of the file public/parser.js. The manipulation of the argument text leads to cross site...Show more |