CWE-79
47,180 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,180)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA. |
A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's browser. The title parameter on the twitter.php endpoint does not properly neutralise user input, resu...Show more |
1Movie Ticket Booking System Project 1Movie Ticket Booking System Jun 17, 2026 Dec 1, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability, which was classified as problematic, was found in Movie Ticket Booking System. Affected is an unknown function of the component POST Request Handler. The manipulation of the argument ORDER_ID leads to cr...Show more |
ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could inject a Persistent XSS payload in the Slideshow Management section that execute ar...Show more |
1Digitalalertsystems 5Dasdec I Firmware Dasdec Ii FirmwareDasdec Iii Firmware+2 moreJun 17, 2026 Dec 1, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via the Host Header in undisclosed pages after login. |
discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rendering content generated with the discourse-bccode plugin. This vulnerability only affects sites whic...Show more |
1Digitalalertsystems 5Dasdec I Firmware Dasdec Ii FirmwareDasdec Iii Firmware+2 moreJun 17, 2026 Nov 30, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH username, username field of...Show more |
SEPPMail's web frontend, user input is not embedded correctly in the web page and therefore leads to cross-site scripting vulnerabilities (XSS). |
Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via Leave, overtime, Manual log. An authenticated employee can read local files by exploiting XSS into a pdf generator when exporting da...Show more |
Zkteco BioTime < 8.5.3 Build:20200816.447 is vulnerable to Incorrect Access Control via resign, private message, manual log, time interval, attshift, and holiday. An authenticated administrator can read local files by ex...Show more |
In Zkteco BioTime < 8.5.3 Build:20200816.447, an employee can hijack an administrator session and cookies using blind cross-site scripting. |
1Rinvizle 1Event Registration System Jun 17, 2026 Nov 30, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability has been found in SourceCodester Event Registration System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /event/admin/?page=user/list. The manip...Show more |
1Dwbooster 1Appointment Hour Booking Jun 17, 2026 Nov 29, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Appointment Hour Booking plugin for WordPress is vulnerable to iFrame Injection via the ‘email’ or general field parameters in versions up to, and including, 1.3.72 due to insufficient input sanitization and output e...Show more |
1Expresstech 1Quiz And Survey Master Jun 17, 2026 Nov 29, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that a...Show more |
The Simple:Press plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sforum_[md5 hash of the WordPress URL]' cookie value in versions up to, and including, 6.8 due to insufficient input sanitiza...Show more |
The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipulated during the profile-save action when modifying a profile signature in versions up to, and includi...Show more |
The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipulated during a forum response in versions up to, and including, 6.8 due to insufficient input sanitiza...Show more |
1Photospace Gallery Project 1Photospace Gallery Jun 17, 2026 Nov 29, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Photospace Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters saved via the update() function in versions up to, and including, 2.3.5 due to insufficient input sanit...Show more |
1Tipsandtricks Hq 1Wp Affiliate Platform Jun 17, 2026 Nov 29, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escaping. This...Show more |
1Tipsandtricks Hq 1Wp Affiliate Platform Jun 17, 2026 Nov 29, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER["REQUEST_URI"] in versions up to, and including, 6.3.9 due to insufficient input sanitization and output escapin...Show more |