← Back
CWE-79

47,152 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,152)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Glpi Project
1Glpi
Jun 17, 2026
Jan 26, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
GLPI is a Free Asset and IT Management Software package. Versions 0.6.0 and above, prior to 10.0.6 are vulnerable to Cross-site Scripting. This vulnerability allow for an administrator to create a malicious external link...Show more
GLPI is a Free Asset and IT Management Software package. Versions 0.6.0 and above, prior to 10.0.6 are vulnerable to Cross-site Scripting. This vulnerability allow for an administrator to create a malicious external link. This issue is patched in 10.0.6.Show less
1Glpi Project
1Glpi
Jun 17, 2026
Jan 26, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
GLPI is a Free Asset and IT Management Software package. Versions prior to 10.0.6 are subject to Cross-site Scripting via malicious RSS feeds. An Administrator can import a malicious RSS feed that contains Cross Site Scr...Show more
GLPI is a Free Asset and IT Management Software package. Versions prior to 10.0.6 are subject to Cross-site Scripting via malicious RSS feeds. An Administrator can import a malicious RSS feed that contains Cross Site Scripting (XSS) payloads inside RSS links. Victims who wish to visit an RSS content and click on the link will execute the Javascript. This issue is patched in 10.0.6. Show less
1Glpi Project
1Glpi
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
GLPI is a Free Asset and IT Management Software package. Versions 9.4.0 and above, prior to 10.0.6 are subject to Cross-site Scripting. An attacker can persuade a victim into opening a URL containing a payload exploiting...Show more
GLPI is a Free Asset and IT Management Software package. Versions 9.4.0 and above, prior to 10.0.6 are subject to Cross-site Scripting. An attacker can persuade a victim into opening a URL containing a payload exploiting this vulnerability. After exploited, the attacker can make actions as the victim or exfiltrate session cookies. This issue is patched in version 10.0.6.Show less
1Discourse
1Discourse
Jun 17, 2026
Jan 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Discourse is an open source platform for community discussion. Versions prior to 2.8.13 (stable), 3.0.0.beta16 (beta) and 3.0.0beta16 (tests-passed), are vulnerable to cross-site Scripting. A maliciously crafted URL can...Show more
Discourse is an open source platform for community discussion. Versions prior to 2.8.13 (stable), 3.0.0.beta16 (beta) and 3.0.0beta16 (tests-passed), are vulnerable to cross-site Scripting. A maliciously crafted URL can be included in a post to carry out cross-site scripting attacks on sites with disabled or overly permissive CSP (Content Security Policy). Discourse's default CSP prevents this vulnerability. This vulnerability is patched in versions 2.8.13 (stable), 3.0.0.beta16 (beta) and 3.0.0beta16 (tests-passed). As a workaround, enable and/or restore your site's CSP to the default one provided with Discourse.Show less
1Iteachyou
1Dreamer Cms
Jun 17, 2026
Jan 26, 2023
N/A· v4
5.4 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability has been found in isoftforce Dreamer CMS up to 4.0.1 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated rem...Show more
A vulnerability has been found in isoftforce Dreamer CMS up to 4.0.1 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.3 is able to address this issue. It is recommended to upgrade the affected component. VDB-219334 is the identifier assigned to this vulnerability.Show less
1Matbao
1Wp Helper Premium
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resulting in a reflected cross-site scripting vulnerability.
1Gitlab
1Gitlab
Jun 17, 2026
Jan 26, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input.
1Small Crm Project
1Small Crm
Jun 17, 2026
Jan 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in the Create Ticket page of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject parameter.
1Online Graduate Tracer System Project
1Online Graduate Tracer System
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Sourcecodester.com Online Graduate Tracer System V 1.0.0 is vulnerable to Cross Site Scripting (XSS).
1Online Graduate Tracer System Project
1Online Graduate Tracer System
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Online Graduate Tracer System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
1Phpgurukul
1Doctor Appointment Management System
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
phpgurukul Doctor Appointment Management System V 1.0.0 is vulnerable to Cross Site Scripting (XSS) via searchdata=.
1Phpgurukul
1Doctor Appointment Management System
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search function.
1Glpi Project
1Glpi
Jun 17, 2026
Jan 26, 2023
N/A· v4
4.8 MEDIUM· v3
N/A· v2
GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6, are subject to Cross-site Scripting. An administrator may store malicious code in help links. This issue is patched in...Show more
GLPI is a Free Asset and IT Management Software package. Versions 10.0.0 and above, prior to 10.0.6, are subject to Cross-site Scripting. An administrator may store malicious code in help links. This issue is patched in 10.0.6.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the...Show more
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that allowed attackers to perform arbitrary actions on behalf of victims.Show less
1Netiq
1Imanager
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious scripts on the user's browser. This issue affects: Micro Focus NetIQ iManager NetIQ iManager versions...Show more
Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious scripts on the user's browser. This issue affects: Micro Focus NetIQ iManager NetIQ iManager versions prior to 3.2.6 on ALL.Show less
1Serve Lite Project
1Serve Lite
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual fi...Show more
All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitization or output encoding. Show less
1Ymfe
1Yapi
Jun 17, 2026
Jan 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api edit page.
1Hfish Project
1Hfish
Jun 17, 2026
Jan 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in HFish 0.5.1. When a payload is inserted where the name is entered, XSS code is triggered when the administrator views the information.
1Idyazilim
1B2b Dealer Order System
Jun 17, 2026
Jan 24, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
B2B Customer Ordering System developed by ID Software Project and Consultancy Services before version 1.0.0.347 has an authenticated Reflected XSS vulnerability. This has been fixed in the version 1.0.0.347.
1Javaweb Blog Project
1Javaweb Blog
Jun 17, 2026
Jan 23, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-Site Scripting (XSS) vulnerability found in Rawchen blog-ssm v1.0 allows attackers to execute arbitrary code via the 'notifyInfo' parameter.