← Back
CWE-79

47,180 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,180)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
110web
1Photo Gallery
Jun 17, 2026
Nov 29, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and type_0 for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, a...Show more
The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and type_0 for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, and CVE-2021-46889. NOTE: VMware information, previously connected to this CVE ID because of a typo, is at CVE-2022-31693.Show less
1Garage Management System Project
1Garage Management System
Jun 17, 2026
Nov 29, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Garage Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /garage/php_action/createBrand.php.
1Discourse
1Discourse
Jun 17, 2026
Nov 29, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.beta11 and prior on the `beta` and `tests-passed` branches, users composing malicious messages and na...Show more
Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.beta11 and prior on the `beta` and `tests-passed` branches, users composing malicious messages and navigating to drafts page could self-XSS. This vulnerability can lead to a full XSS on sites which have modified or disabled Discourse’s default Content Security Policy. This issue is patched in the latest stable, beta and tests-passed versions of Discourse.Show less
1Contec
1Solarview Compact Firmware
Jun 17, 2026
Nov 29, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SolarView Compact 7.0 is vulnerable to Cross-site Scripting (XSS) via /network_test.php.
1Amasty
1Amasty Blog Pro
Jun 17, 2026
Nov 29, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript code in the short_content and full_content fields, leading to XSS attacks against admin panel users v...Show more
The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript code in the short_content and full_content fields, leading to XSS attacks against admin panel users via posts/preview or posts/save.Show less
1Klik Project
1Klik
Jun 17, 2026
Nov 29, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location input reply-form.
1Klik Project
1Klik
Jun 17, 2026
Nov 29, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location Forum Subject input.
1Raidenmaild
1Raidenmaild
Jun 17, 2026
Nov 29, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Raiden MAILD Mail Server website mail field has insufficient filtering for user input. A remote attacker with general user privilege can send email using the website with malicious JavaScript in the input field, which tr...Show more
Raiden MAILD Mail Server website mail field has insufficient filtering for user input. A remote attacker with general user privilege can send email using the website with malicious JavaScript in the input field, which triggers XSS (Reflected Cross-Site Scripting) attack to the mail recipient.Show less
1Churchcrm
1Churchcrm
Jun 17, 2026
Nov 29, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
ChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input sHeader.
1Churchcrm
1Churchcrm
Jun 17, 2026
Nov 29, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
ChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input Deposit Comment.
1Web Based Student Clearance System Project
1Web Based Student Clearance System
Jun 17, 2026
Nov 28, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in Admin/add-admin.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a craf...Show more
Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in Admin/add-admin.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtfullname parameter.Show less
1Web Based Student Clearance System Project
1Web Based Student Clearance System
Jun 17, 2026
Nov 28, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /Admin/add-student.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a c...Show more
Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /Admin/add-student.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtfullname parameter.Show less
1Web Based Student Clearance System Project
1Web Based Student Clearance System
Jun 17, 2026
Nov 28, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in changepassword.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a craft...Show more
Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in changepassword.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtnew_password parameter.Show less
1Sanitization Management System Project
1Sanitization Management System
Jun 17, 2026
Nov 28, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Sanitization Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter at /php-sms/classes...Show more
A cross-site scripting (XSS) vulnerability in Sanitization Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter at /php-sms/classes/Login.php.Show less
1Open.edx
1Xblock Drag And Drop V2
Jun 17, 2026
Nov 28, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0.0 are vulnerable to cross-site scripting in multiple XBlock Fields. An...Show more
Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0.0 are vulnerable to cross-site scripting in multiple XBlock Fields. Any platform that has deployed the XBlock may be impacted. Version 3.0.0 contains a patch for this issue. There are no known workarounds.Show less
1Dinstar
1Dag2000 16o Firmware
Jun 17, 2026
Nov 28, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Dinstar FXO Analog VoIP Gateway DAG2000-16O is vulnerable to Cross Site Scripting (XSS).
1Google Forms Project
1Google Forms
Jun 17, 2026
Nov 28, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Google Forms WordPress plugin through 0.95 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilter...Show more
The Google Forms WordPress plugin through 0.95 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).Show less
1Book Store Management System Project
1Book Store Management System
Jun 17, 2026
Nov 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafte...Show more
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the book_title parameter.Show less
1Nextcloud
1Desktop
Jun 17, 2026
Nov 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application. It is recommended that the Nextcloud Desktop client is upgraded t...Show more
Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue.Show less
1Nextcloud
1Desktop
Jun 17, 2026
Nov 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application via user status and information. It is recommended that the Nextcl...Show more
Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application via user status and information. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue.Show less