CWE-79
47,153 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,153)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
13commarketing 13com Asesor De Cookies Jun 17, 2026 Jan 19, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in 3com – Asesor de Cookies para normativa española plugin <= 3.4.3 versions. |
A vulnerability was found in MyCMS. It has been classified as problematic. This affects the function build_view of the file lib/gener/view.php of the component Visitors Module. The manipulation of the argument original/c...Show more |
RushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious application. This is possible because the application exposes an activity and does not properly validate the d...Show more |
1Ibm 3Robotic Process Automation Robotic Process Automation As A ServiceRobotic Process Automation For Cloud PakJun 17, 2026 Jan 18, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 IBM Robotic Process Automation for Cloud Pak 20.12.0 through 21.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended funct...Show more |
1Book Store Management System Project 1Book Store Management System Jun 17, 2026 Jan 18, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafte...Show more |
1Trellix 1Skyhigh Secure Web Gateway Jun 17, 2026 Jan 18, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A cross-site scripting vulnerability in Skyhigh SWG in main releases 11.x prior to 11.2.6, 10.x prior to 10.2.17, and controlled release 12.x prior to 12.0.1 allows a remote attacker to craft SWG-specific internal reques...Show more |
A vulnerability classified as problematic has been found in GENI Portal. This affects the function no_invocation_id_error of the file portal/www/portal/sliceresource.php. The manipulation of the argument invocation_id/in...Show more |
A vulnerability was found in GENI Portal. It has been rated as problematic. Affected by this issue is some unknown functionality of the file portal/www/portal/error-text.php. The manipulation of the argument error leads...Show more |
1Sewio 1Real Time Location System Studio Jun 17, 2026 Jan 18, 2023 N/A· v4 9.6 CRITICAL· v3 N/A· v2 Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-site scripting in its backup services. An attacker could take advantage of this vulnerability to exec...Show more |
IMPatienT before 1.5.2 allows stored XSS via onmouseover in certain text fields within a PATCH /modify_onto request to the ontology builder. This may allow attackers to steal Protected Health Information. |
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter. |
1Phoronix Media 1Phoronix Test Suite Jun 17, 2026 Jan 17, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A XSS vulnerability was found in phoromatic_r_add_test_details.php in phoronix-test-suite. |
Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch. |
Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch. |
1Webapplication Veganguide Project 1Webapplication Veganguide Nov 21, 2024 Jan 17, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability has been found in s134328 Webapplication-Veganguide and classified as problematic. This vulnerability affects unknown code of the file p05-integration/app/shared/api/apiService.js. The manipulation of the...Show more |
1Mediawiki 1Wikisource Category Browser Nov 21, 2024 Jan 17, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability, which was classified as problematic, was found in Wikisource Category Browser. This affects an unknown part of the file index.php. The manipulation of the argument lang leads to cross site scripting. It...Show more |
1Ate Mahoroba 3Maho Pbx Netdevancer Firmware Maho Pbx Netdevancer Mobilegate FirmwareMaho Pbx Netdevancer Vsg FirmwareJun 17, 2026 Jan 17, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Reflected cross-site scripting vulnerability in MAHO-PBX NetDevancer series MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer M...Show more |
1Simplesamlphp 1Simplesamlphp Module Openidprovider Nov 21, 2024 Jan 17, 2023 N/A· v4 5.4 MEDIUM· v3 4.0 MEDIUM· v2 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in simplesamlphp simplesamlphp-module-openidprovider up to 0.8.x. It has been declared as problematic. Affected by this vulnerability is an unknown functionality...Show more |
2Ad33lx Ip Blacklist Cloud Project2Ip Blacklist Cloud Ip Blacklist CloudJun 17, 2026 Jan 17, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. Stored Cross-Site Scripting (XSS) vulnerability in Adeel Ahmed's IP Blacklist Cloud plugin <= 5.00 versions. |
1Theradsystem Project 1Theradsystem Jun 17, 2026 Jan 16, 2023 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in saemorris TheRadSystem. It has been classified as problematic. Affected is an unknown function of the file users.php. The manipulation of the argument q leads to cross site scripting. It is p...Show more |