← Back
CWE-79

47,152 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,152)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Online Food Ordering System Project
Oretnom23
2Online Food Ordering System
Online Food Ordering System
Jun 17, 2026
Feb 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php.
2Online Food Ordering System Project
Oretnom23
2Online Food Ordering System
Online Food Ordering System
Jun 17, 2026
Feb 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php.
2Online Food Ordering System Project
Oretnom23
2Online Food Ordering System
Online Food Ordering System
Jun 17, 2026
Feb 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in navbar.php.
2Online Food Ordering System Project
Oretnom23
2Online Food Ordering System
Online Food Ordering System
Jun 17, 2026
Feb 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php.
2Online Food Ordering System Project
Oretnom23
2Online Food Ordering System
Online Food Ordering System
Jun 17, 2026
Feb 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php.
1Softr
1Softr
Jul 9, 2026
Feb 6, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter.
1Gzwhir
1Ezeip
Jun 17, 2026
Feb 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
ezEIP v5.3.0(0649) was discovered to contain a cross-site scripting (XSS) vulnerability.
1Afterpay
1Afterpay Gateway For Woocommerce
Jun 17, 2026
Feb 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Afterpay Gateway for WooCommerce <= 3.5.0 versions.
1Share On Diaspora Project
1Share On Diaspora
Nov 21, 2024
Feb 6, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability classified as problematic was found in ciubotaru share-on-diaspora 0.7.9. This vulnerability affects unknown code of the file new_window.php. The manipulation of the argument title/url leads to cross site...Show more
A vulnerability classified as problematic was found in ciubotaru share-on-diaspora 0.7.9. This vulnerability affects unknown code of the file new_window.php. The manipulation of the argument title/url leads to cross site scripting. The attack can be initiated remotely. The name of the patch is fb6fae2f8a9b146471450b5b0281046a17d1ac8d. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-220204.Show less
1Mediawiki
1Matomo
Nov 21, 2024
Feb 5, 2023
N/A· v4
6.1 MEDIUM· v3
2.1 LOW· v2
A vulnerability classified as problematic has been found in DaSchTour matomo-mediawiki-extension up to 2.4.2 on MediaWiki. This affects an unknown part of the file Piwik.hooks.php of the component Username Handler. The m...Show more
A vulnerability classified as problematic has been found in DaSchTour matomo-mediawiki-extension up to 2.4.2 on MediaWiki. This affects an unknown part of the file Piwik.hooks.php of the component Username Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.4.3 is able to address this issue. The patch is named 681324e4f518a8af4bd1f93867074c728eb9923d. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-220203.Show less
1Apache
1Sling Cms
Jun 17, 2026
Feb 4, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and prior may allow an authenticated remote attacker to perform a reflected cr...Show more
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling App CMS version 1.1.4 and prior may allow an authenticated remote attacker to perform a reflected cross-site scripting (XSS) attack in multiple features. Upgrade to Apache Sling App CMS >= 1.1.6 Show less
1Phpipam
1Phpipam
Jun 17, 2026
Feb 4, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1.
1Phpipam
1Phpipam
Jun 17, 2026
Feb 4, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.
1Mobiledetect
1Mobiledetect
Apr 16, 2025
Feb 4, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability, which was classified as problematic, has been found in MobileDetect 2.8.31. This issue affects the function initLayoutType of the file examples/session_example.php of the component Example. The manipulat...Show more
A vulnerability, which was classified as problematic, has been found in MobileDetect 2.8.31. This issue affects the function initLayoutType of the file examples/session_example.php of the component Example. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.8.32 is able to address this issue. The identifier of the patch is 31818a441b095bdc4838602dbb17b8377d1e5cce. It is recommended to upgrade the affected component. The identifier VDB-220061 was assigned to this vulnerability.Show less
1Nrel
1Api Umbrella Web
Nov 21, 2024
Feb 4, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability classified as problematic was found in NREL api-umbrella-web 0.7.1. This vulnerability affects unknown code of the component Flash Message Handler. The manipulation leads to cross site scripting. The atta...Show more
A vulnerability classified as problematic was found in NREL api-umbrella-web 0.7.1. This vulnerability affects unknown code of the component Flash Message Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 0.8.0 is able to address this issue. The name of the patch is bcc0e922c61d30367678c8f17a435950969315cd. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-220060.Show less
1Wepanow
1Print Away
Jun 17, 2026
Feb 3, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
WEPA Print Away does not verify that a user has authorization to access documents before generating print orders and associated release codes. This could allow an attacker to generate print orders and release codes for d...Show more
WEPA Print Away does not verify that a user has authorization to access documents before generating print orders and associated release codes. This could allow an attacker to generate print orders and release codes for documents they don´t own and print hem without authorization. In order to exploit this vulnerability, the user must have an account with wepanow.com or any of the institutions they serve, and be logged in.Show less
1Wepanow
1Print Away
Jun 17, 2026
Feb 3, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
WEPA Print Away is vulnerable to a stored XSS. It does not properly sanitize uploaded filenames, allowing an attacker to deceive a user into uploading a document with a malicious filename, which will be included in subse...Show more
WEPA Print Away is vulnerable to a stored XSS. It does not properly sanitize uploaded filenames, allowing an attacker to deceive a user into uploading a document with a malicious filename, which will be included in subsequent HTTP responses, allowing a stored XSS to occur. This attack is persistent across victim sessions.Show less
1Vimium Project
1Vimium
Jun 17, 2026
Feb 3, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Universal Cross Site Scripting (UXSS) vulnerability in Vimium Extension 1.66 and earlier allows remote attackers to run arbitrary code via omnibar feature.
1Automad
1Automad
Jun 17, 2026
Feb 3, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in automad 1.7.5 allows remote attackers to run arbitrary code via the user name field when adding a user.
1Teradek
1Sphere Firmware
Jun 17, 2026
Feb 3, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in Teradek Sphere all firmware versions allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product ha...Show more
Cross Site Scripting (XSS) vulnerability in Teradek Sphere all firmware versions allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.Show less