← Back
CWE-79

47,152 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,152)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Opencats
1Opencats
Jun 17, 2026
Jan 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.php?m=calendar. This vulnerability allows attackers to execute arbitrary web scripts or HTML vi...Show more
Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/index.php?m=calendar. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description or Title text fields.Show less
1Opencats
1Opencats
Jun 17, 2026
Jan 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /opencats/index.php?m=settings&a=ajax_tags_upd.
1Limesurvey
1Limesurvey
Jun 17, 2026
Jan 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.php/surveyAdministration/rendersidemenulink?subaction=surveytexts. This vulnerability allows attacker...Show more
LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.php/surveyAdministration/rendersidemenulink?subaction=surveytexts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description or Welcome-message text fields. NOTE: the vendor indicates that this is not a vulnerability because the manipulation requires Superadministrator privileges, and Superadministrators are already allowed to customize surveys with JavaScript as they wish.Show less
1Piwigo
1Piwigo
Jun 17, 2026
Jan 27, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in identification.php of Piwigo v13.4.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User-Agent.
1Netscout
1Ngeniusone
Jun 17, 2026
Jan 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 6 of 6.
1Netscout
1Ngeniusone
Jun 17, 2026
Jan 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 5 of 6.
1Netscout
1Ngeniusone
Jun 17, 2026
Jan 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 4 of 6.
1Netscout
1Ngeniusone
Jun 17, 2026
Jan 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 3 of 6.
1Netscout
1Ngeniusone
Jun 17, 2026
Jan 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 2 of 6.
1Netscout
1Ngeniusone
Jun 17, 2026
Jan 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 1 of 6.
1Online Security Guards Hiring System Project
1Online Security Guards Hiring System
Jun 17, 2026
Jan 27, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file search-request.php. The manipulation of the...Show more
A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file search-request.php. The manipulation of the argument searchdata with the input "><script>alert(document.domain)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219596.Show less
1Modoboa
1Modoboa
Jun 17, 2026
Jan 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4.
2Pyload
Pyload Ng Project
2Pyload
Pyload Ng
Jun 17, 2026
Jan 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository pyload/pyload prior to 0.5.0b3.dev42.
1Modoboa
1Modoboa
Jun 17, 2026
Jan 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4.
1Baicells
2Rtd Firmware
Rts Firmware
Jun 17, 2026
Jan 26, 2023
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using...Show more
Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been tested and validated by a 3rd party analyst and has been confirmed exploitable special thanks to Rustam Amin for providing the steps to reproduce.  Show less
1Tenable
1Tenable.sc
Jun 17, 2026
Jan 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated, remote attacker can exploit this by convincing a us...Show more
A stored cross-site scripting (XSS) vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated, remote attacker can exploit this by convincing a user to click a specially crafted URL, to execute arbitrary script code in a user's browser session.Show less
1Broadcom
2Symantec Identity Governance And Administration
Symantec Identity Manager
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
1Broadcom
2Symantec Identity Governance And Administration
Symantec Identity Manager
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.
1Broadcom
2Symantec Identity Governance And Administration
Symantec Identity Manager
Jun 17, 2026
Jan 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.
1Hughes
5Hn7000s Firmware
Hn9460 FirmwareHx200 Firmware+2 more
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in Hughes Network Systems Router Terminal for HX200 v8.3.1.14, HX90 v6.11.0.5, HX50L v6.10.0.18, HN9460 v8.2.0.48, and HN7000S v6.9.0.37, allows unauthenticated attackers to misus...Show more
Cross Site Scripting (XSS) vulnerability in Hughes Network Systems Router Terminal for HX200 v8.3.1.14, HX90 v6.11.0.5, HX50L v6.10.0.18, HN9460 v8.2.0.48, and HN7000S v6.9.0.37, allows unauthenticated attackers to misuse frames, include JS/HTML code and steal sensitive information from legitimate users of the application.Show less