CWE-79
47,169 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,169)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Dec 19, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable...Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Dec 19, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable...Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Dec 19, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable...Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Dec 19, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable...Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Dec 19, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable...Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Dec 19, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable...Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Dec 19, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable...Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Dec 19, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable...Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Dec 19, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable...Show more |
1Adobe 2Experience Manager Experience Manager Cloud ServiceJun 17, 2026 Dec 19, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable...Show more |
1Employee Performance Evaluation System Project 1Employee Performance Evaluation System Jul 9, 2026 Dec 19, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Departments and Designations module. |
The Responsive Lightbox2 WordPress plugin before 1.0.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to p...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0. |
Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and cache poisoning attacks.This issue affects Apache Traffic Server: 9.0...Show more |
A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Affected is an unknown function of the component URL Field Handler. The manipulat...Show more |
In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded.
|
1Jacic 1Electronic Bidding Core System Jun 17, 2026 Dec 19, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-site scripting vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to inject an arbitrary script. |
1Jacic 1Electronic Bidding Core System Jun 17, 2026 Dec 19, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-site scripting vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to inject an arbitrary script. |
A vulnerability was found in ctrlo lenio. It has been declared as problematic. This vulnerability affects unknown code of the file views/task.tt of the component Task Handler. The manipulation of the argument site.org.na...Show more |
A vulnerability was found in ctrlo lenio. It has been classified as problematic. This affects an unknown part of the file views/index.tt. The manipulation of the argument task.name/task.site.org.name leads to cross site...Show more |