← Back
CWE-79

47,152 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,152)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Infosphere Information Server
Jun 17, 2026
Feb 8, 2023
N/A· v4
4.6 MEDIUM· v3
N/A· v2
IBM Infosphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more
IBM Infosphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245423.Show less
1Eyoucms
1Eyoucms
Jun 17, 2026
Feb 8, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site scripting (XSS) vulnerability in EyouCMS v1.6.0 allows attackers to execute arbitrary code via the home page description on the basic information page.
1Ibm
1Sterling Secure Proxy
Jun 17, 2026
Feb 8, 2023
N/A· v4
4.6 MEDIUM· v3
N/A· v2
IBM Sterling Secure Proxy 6.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system,...Show more
IBM Sterling Secure Proxy 6.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 230523. Show less
1Btcpayserver
1Btcpayserver
Jun 17, 2026
Feb 8, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
1Answer
1Answer
Jun 17, 2026
Feb 8, 2023
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4.
1Answer
1Answer
Jun 17, 2026
Feb 8, 2023
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
1Answer
1Answer
Jun 17, 2026
Feb 8, 2023
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.
1Answer
1Answer
Jun 17, 2026
Feb 8, 2023
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
1Simple Sales Management System Project
1Simple Sales Management System
Jun 17, 2026
Feb 7, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross site scripting (XSS) vulnerability in sourcecodester oretnom23 sales management system 1.0, allows attackers to execute arbitrary code via the product_name and product_price inputs in file print.php.
1Invoiceplane
1Invoiceplane
Jun 17, 2026
Feb 7, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php.
1Wallabag
1Wallabag
Jun 17, 2026
Feb 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository wallabag/wallabag prior to 2.5.4.
1Interactive Geo Maps Project
1Interactive Geo Maps
Jun 17, 2026
Feb 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Interactive Geo Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the action content parameter in versions up to, and including, 1.5.9 due to insufficient input sanitization and output escapi...Show more
The Interactive Geo Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the action content parameter in versions up to, and including, 1.5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with editor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Logicaldoc
1Logicaldoc
Jun 17, 2026
Feb 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the document version comments.
1Mayan Edms
1Mayan Edms
Jun 17, 2026
Feb 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An XSS vulnerability was discovered in the Mayan EDMS DMS. Successful XSS exploitation was observed in the in-product tagging system.
1Logicaldoc
1Logicaldoc
Jun 17, 2026
Feb 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the document file name.
1Logicaldoc
1Logicaldoc
Jun 17, 2026
Feb 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
LogicalDOC Enterprise is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the in-app chat system.
1Logicaldoc
1Logicaldoc
Jun 17, 2026
Feb 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the in-app messaging system (both subject and message bodies).
1Openkm
1Openkm
Jun 17, 2026
Feb 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in the document "note" functionality.
1Openkm
1Openkm
Jun 17, 2026
Feb 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II") XSS condition.
1Oretnom23
1Online Eyewear Shop
Jun 17, 2026
Feb 7, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is the function registration of the file oews/classes/Users.php of the component POST...Show more
A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is the function registration of the file oews/classes/Users.php of the component POST Request Handler. The manipulation of the argument firstname/middlename/lastname/email/contact leads to cross site scripting. The attack can be launched remotely. The identifier VDB-220369 was assigned to this vulnerability.Show less