← Back
CWE-79

47,161 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,161)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Indeed
1Util
Jun 17, 2026
Dec 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability classified as problematic has been found in Indeed Engineering util up to 1.0.33. Affected is the function visit/appendTo of the file varexport/src/main/java/com/indeed/util/varexport/servlet/ViewExported...Show more
A vulnerability classified as problematic has been found in Indeed Engineering util up to 1.0.33. Affected is the function visit/appendTo of the file varexport/src/main/java/com/indeed/util/varexport/servlet/ViewExportedVariablesServlet.java. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.0.34 is able to address this issue. The name of the patch is c0952a9db51a880e9544d9fac2a2218a6bfc9c63. It is recommended to upgrade the affected component. VDB-216882 is the identifier assigned to this vulnerability.Show less
1Sangoma
1Freepbx
Jun 17, 2026
Dec 27, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A vulnerability was found in FreePBX arimanager up to 13.0.5.3 and classified as problematic. Affected by this issue is some unknown functionality of the component Views Handler. The manipulation of the argument dataurl...Show more
A vulnerability was found in FreePBX arimanager up to 13.0.5.3 and classified as problematic. Affected by this issue is some unknown functionality of the component Views Handler. The manipulation of the argument dataurl leads to cross site scripting. The attack may be launched remotely. Upgrading to version 13.0.5.4 is able to address this issue. The name of the patch is 199dea7cc7020d3c469a86a39fbd80f5edd3c5ab. It is recommended to upgrade the affected component. VDB-216878 is the identifier assigned to this vulnerability.Show less
1Nagios
1Nagios Cross Platform Agent
Jun 17, 2026
Dec 27, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A vulnerability classified as problematic was found in Nagios NCPA. This vulnerability affects unknown code of the file agent/listener/templates/tail.html. The manipulation of the argument name leads to cross site script...Show more
A vulnerability classified as problematic was found in Nagios NCPA. This vulnerability affects unknown code of the file agent/listener/templates/tail.html. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 2.4.0 is able to address this issue. The name of the patch is 5abbcd7aa26e0fc815e6b2b0ffe1c15ef3e8fab5. It is recommended to upgrade the affected component. VDB-216874 is the identifier assigned to this vulnerability.Show less
1Flatpress
1Flatpress
Jun 17, 2026
Dec 27, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A vulnerability was found in FlatPress and classified as problematic. This issue affects the function main of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component Media Manager Plugin. The...Show more
A vulnerability was found in FlatPress and classified as problematic. This issue affects the function main of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component Media Manager Plugin. The manipulation of the argument mm-newgallery-name leads to cross site scripting. The attack may be initiated remotely. The name of the patch is d3f329496536dc99f9707f2f295d571d65a496f5. It is recommended to apply a patch to fix this issue. The identifier VDB-216869 was assigned to this vulnerability.Show less
1Openmrs
1Htmlformentryui
Jun 17, 2026
Dec 27, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A vulnerability classified as problematic has been found in OpenMRS HTML Form Entry UI Framework Integration Module up to 1.x. This affects an unknown part. The manipulation leads to cross site scripting. It is possible...Show more
A vulnerability classified as problematic has been found in OpenMRS HTML Form Entry UI Framework Integration Module up to 1.x. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.0.0 is able to address this issue. The name of the patch is 811990972ea07649ae33c4b56c61c3b520895f07. It is recommended to upgrade the affected component. The identifier VDB-216873 was assigned to this vulnerability.Show less
1Sangoma
1Voicemail
Jun 17, 2026
Dec 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability was found in FreeBPX voicemail. It has been rated as problematic. Affected by this issue is some unknown functionality of the file views/ssettings.php of the component Settings Handler. The manipulation o...Show more
A vulnerability was found in FreeBPX voicemail. It has been rated as problematic. Affected by this issue is some unknown functionality of the file views/ssettings.php of the component Settings Handler. The manipulation of the argument key leads to cross site scripting. The attack may be launched remotely. Upgrading to version 14.0.6.25 is able to address this issue. The name of the patch is ffce4882016076acd16fe0f676246905aa3cb2f3. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216872.Show less
1Sangoma
1Voicemail
Jun 17, 2026
Dec 27, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A vulnerability was found in FreePBX voicemail. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file page.voicemail.php. The manipulation leads to cross site scripti...Show more
A vulnerability was found in FreePBX voicemail. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file page.voicemail.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 14.0.6.25 is able to address this issue. The name of the patch is 12e1469ef9208eda9d8955206e78345949236ee6. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216871.Show less
1Oxidized Web Project
1Oxidized Web
Jun 17, 2026
Dec 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability was found in ytti Oxidized Web. It has been classified as problematic. Affected is an unknown function of the file lib/oxidized/web/views/conf_search.haml. The manipulation of the argument to_research lea...Show more
A vulnerability was found in ytti Oxidized Web. It has been classified as problematic. Affected is an unknown function of the file lib/oxidized/web/views/conf_search.haml. The manipulation of the argument to_research leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45. It is recommended to apply a patch to fix this issue. VDB-216870 is the identifier assigned to this vulnerability.Show less
1Open
1Open Media Player
Jun 17, 2026
Dec 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability was found in IET-OU Open Media Player up to 1.5.0. It has been declared as problematic. This vulnerability affects the function webvtt of the file application/controllers/timedtext.php. The manipulation o...Show more
A vulnerability was found in IET-OU Open Media Player up to 1.5.0. It has been declared as problematic. This vulnerability affects the function webvtt of the file application/controllers/timedtext.php. The manipulation of the argument ttml_url leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.5.1 is able to address this issue. The name of the patch is 3f39f2d68d11895929c04f7b49b97a734ae7cd1f. It is recommended to upgrade the affected component. VDB-216862 is the identifier assigned to this vulnerability.Show less
1Adiscon
1Password Manager For Iis
Jun 17, 2026
Dec 26, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter.
1Ljapps
1Wp Google Review Slider
Jun 17, 2026
Dec 26, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The WP Google Review Slider WordPress plugin before 11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when th...Show more
The WP Google Review Slider WordPress plugin before 11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).Show less
6Ht Slider Range For Amazon Affiliates Project
Php Curl Class ProjectPtwooplugins+3 more
6Ht Slider Range For Amazon Affiliates
Invoicing With Invoicexpress For WoocommercePhp Curl Class+3 more
Jun 17, 2026
Dec 26, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.
1Mediawiki
1Mediawiki
Jun 17, 2026
Dec 26, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Dec 26, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Dec 26, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Dec 26, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Dec 26, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Dec 26, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Dec 26, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Dec 26, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.