CWE-79
47,164 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,164)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Mozilla2Debian Linux FirefoxJun 17, 2026 Dec 22, 2022 N/A· v4 4.3 MEDIUM· v3 N/A· v2 By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 108. |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Dec 22, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies inaccessible to JavaScript (such as cookies protected by HTTPOn...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Dec 22, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerabi...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Dec 22, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox...Show more |
If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>http-equiv="refresh"</code> attribute, and the content attribute specifying an URL...Show more |
SVG <code><use></code> tags that referenced a same-origin document could have resulted in script execution if attacker input was sanitized via the HTML Sanitizer API. This would have required the attacker to refere...Show more |
The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code><use></code> tags; however it incorrectly did not sanitize <code>xlink:href</code> attributes. This vulnerability affects Firefo...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Dec 22, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. This vulnerability affects Firefox ESR < 91.11, Thunderbird <...Show more |
Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controlled data in them. This...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Dec 22, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunder...Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Dec 22, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2. |
Inhabit Systems Pty Ltd Move CRM version 4, build 260 was discovered to contain a cross-site scripting (XSS) vulnerability via the User profile component. |
1Simple Client Management System Project 1Simple Client Management System Jun 17, 2026 Dec 22, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A Stored Cross-site scripting (XSS) vulnerability via MAster.php in Sourcecodetester Simple Client Management System (SCMS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the vulnerable input fiel...Show more |
A vulnerability was found in tatoeba2. It has been classified as problematic. This affects an unknown part of the component Profile Name Handler. The manipulation leads to cross site scripting. It is possible to initiate...Show more |
1Collective.contact.widget Project 1Collective.contact.widget Jun 17, 2026 Dec 21, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability classified as problematic was found in collective.contact.widget up to 1.12. This vulnerability affects the function title of the file src/collective/contact/widget/widgets.py. The manipulation leads to c...Show more |
1Ep 3bookingsystem 1Ep 3 Bookingsystem Jun 17, 2026 Dec 21, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability classified as problematic has been found in ep3-bs up to 1.7.x. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to v...Show more |
1Auto Upload Images Project 1Auto Upload Images Jun 17, 2026 Dec 21, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability has been found in Auto Upload Images up to 3.3.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can b...Show more |
A vulnerability, which was classified as problematic, was found in WP-Ban. Affected is an unknown function of the file ban-options.php. The manipulation leads to cross site scripting. It is possible to launch the attack...Show more |
1Covid 19 Directory On Vaccination System Project 1Covid 19 Directory On Vaccination System Jun 17, 2026 Dec 21, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A Cross site scripting (XSS) vulnerability in Sourcecodester Online Covid-19 Directory on Vaccination System v1.0 allows attackers to execute arbitrary code via the txtfullname parameter or txtphone parameter to register...Show more |