← Back
CWE-79

47,180 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,180)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Basercms
1Basercms
Jun 17, 2026
Nov 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be ad...Show more
BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scripting vulnerability on the management system of baserCMS. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. Users of baserCMS are advised to upgrade as soon as possible. There are no known workarounds for this vulnerability.Show less
1Nextcloud
1Openid Connect User Backend
Jun 17, 2026
Nov 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery urls which may lead to a stored cross site scripting attack vector. The impact is limited due to the...Show more
user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery urls which may lead to a stored cross site scripting attack vector. The impact is limited due to the restrictive CSP that is applied on this endpoint. Additionally this vulnerability has only been shown to be exploitable in the Safari web browser. This issue has been addressed in version 1.2.1. Users are advised to upgrade. Users unable to upgrade should urge their users to avoid using the Safari web browser.Show less
1Nextcloud
1Desktop
Jun 17, 2026
Nov 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application in the notifications. It is recommended that the Nextcloud Desktop...Show more
Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language into the Desktop Client application in the notifications. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.1. There are no known workarounds for this issue.Show less
1Spatie
1Browsershot
Jun 17, 2026
Nov 25, 2022
N/A· v4
8.2 HIGH· v3
N/A· v2
Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.
1Microweber
1Microweber
Jun 17, 2026
Nov 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.
1Oretnom23
1Human Resource Management System
Jun 17, 2026
Nov 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Human Resource Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability. This vulnerability is triggered via a crafted payload injected into an authentication error message.
1Spatie
1Browsershot
Jun 17, 2026
Nov 25, 2022
N/A· v4
8.2 HIGH· v3
N/A· v2
Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content imported from an external source passed to t...Show more
Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content imported from an external source passed to the Browsershot::html method does not contain URLs that use the file:// protocol.Show less
1Spatie
1Browsershot
Jun 17, 2026
Nov 25, 2022
N/A· v4
8.2 HIGH· v3
N/A· v2
Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the HTML content passed to the Browsershot::html method doe...Show more
Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the HTML content passed to the Browsershot::html method does not contain URL's that use the file:// protocol.Show less
1Pyrocms
1Pyrocms
Jul 9, 2026
Nov 25, 2022
N/A· v4
9.0 CRITICAL· v3
N/A· v2
PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privi...Show more
PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation.Show less
1Wbce
1Wbce Cms
Jun 17, 2026
Nov 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in /admin/pages/sections_save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name Section field.
1Wbce
1Wbce Cms
Jun 17, 2026
Nov 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Website Footer field.
1Wbce
1Wbce Cms
Jun 17, 2026
Nov 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name field.
1Wbce
1Wbce Cms
Jun 17, 2026
Nov 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the No Results field.
1Orchardcore
1Orchard Cms
Jul 9, 2026
Nov 25, 2022
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admi...Show more
Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation when the malicious blog post is loaded in the victim's browser.Show less
1Stock Management System Project
1Stock Management System
Jun 17, 2026
Nov 24, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability was found in rickxy Stock Management System. It has been declared as problematic. This vulnerability affects unknown code of the file /pages/processlogin.php. The manipulation of the argument user leads t...Show more
A vulnerability was found in rickxy Stock Management System. It has been declared as problematic. This vulnerability affects unknown code of the file /pages/processlogin.php. The manipulation of the argument user leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214324.Show less
1Eyoucms
1Eyoucms
Jun 17, 2026
Nov 23, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in the Url parameter in /login.php of EyouCMS v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
1Solarwinds
1Security Event Manager
Jun 17, 2026
Nov 23, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lead to HTTP request smuggling or XSS.
1Amasty
1Blog Pro
Jul 9, 2026
Nov 23, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the duplicate post function.
2Fedoraproject
Moodle
2Fedora
Moodle
Jun 17, 2026
Nov 23, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and s...Show more
The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.Show less
2Fedoraproject
Moodle
2Fedora
Moodle
Jun 17, 2026
Nov 23, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafte...Show more
A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link that executes an arbitrary HTML and script code in user's browser in context of vulnerable website. This vulnerability may allow an attacker to perform cross-site scripting (XSS) attacks to gain access potentially sensitive information and modification of web pages.Show less