CWE-79
47,161 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,161)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability classified as problematic has been found in Indeed Engineering util up to 1.0.33. Affected is the function visit/appendTo of the file varexport/src/main/java/com/indeed/util/varexport/servlet/ViewExported...Show more |
A vulnerability was found in FreePBX arimanager up to 13.0.5.3 and classified as problematic. Affected by this issue is some unknown functionality of the component Views Handler. The manipulation of the argument dataurl...Show more |
1Nagios 1Nagios Cross Platform Agent Jun 17, 2026 Dec 27, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability classified as problematic was found in Nagios NCPA. This vulnerability affects unknown code of the file agent/listener/templates/tail.html. The manipulation of the argument name leads to cross site script...Show more |
A vulnerability was found in FlatPress and classified as problematic. This issue affects the function main of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component Media Manager Plugin. The...Show more |
A vulnerability classified as problematic has been found in OpenMRS HTML Form Entry UI Framework Integration Module up to 1.x. This affects an unknown part. The manipulation leads to cross site scripting. It is possible...Show more |
A vulnerability was found in FreeBPX voicemail. It has been rated as problematic. Affected by this issue is some unknown functionality of the file views/ssettings.php of the component Settings Handler. The manipulation o...Show more |
A vulnerability was found in FreePBX voicemail. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file page.voicemail.php. The manipulation leads to cross site scripti...Show more |
1Oxidized Web Project 1Oxidized Web Jun 17, 2026 Dec 27, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability was found in ytti Oxidized Web. It has been classified as problematic. Affected is an unknown function of the file lib/oxidized/web/views/conf_search.haml. The manipulation of the argument to_research lea...Show more |
A vulnerability was found in IET-OU Open Media Player up to 1.5.0. It has been declared as problematic. This vulnerability affects the function webvtt of the file application/controllers/timedtext.php. The manipulation o...Show more |
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter. |
The WP Google Review Slider WordPress plugin before 11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when th...Show more |
6Ht Slider Range For Amazon Affiliates Project Php Curl Class ProjectPtwooplugins+3 more6Ht Slider Range For Amazon Affiliates Invoicing With Invoicexpress For WoocommercePhp Curl Class+3 moreJun 17, 2026 Dec 26, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php. |
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature. |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Dec 26, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI. |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Dec 26, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name. |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Dec 26, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message. |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Dec 26, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked. |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Dec 26, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages. |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Dec 26, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature. |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Dec 26, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI. |