← Back
CWE-79

47,180 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,180)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Caehealthcare
1Learningspace Enterprise
Jun 17, 2026
Nov 23, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup.
1Silverstripe
1Framework
Jun 17, 2026
Nov 23, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).
1Silverstripe
1Silverstripe
Jun 17, 2026
Nov 23, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Silverstripe silverstripe/cms through 4.11.0 allows XSS.
1Backdropcms
1Backdrop Cms
Jun 17, 2026
Nov 23, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.
1Silverstripe
1Framework
Jun 17, 2026
Nov 23, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view.
1Silverstripe
1Framework
Jun 17, 2026
Nov 23, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).
1Silverstripe
1Framework
Jun 17, 2026
Nov 23, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters.
1Amasty
1Blog Pro
Jul 9, 2026
Nov 23, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality.
1Silverstripe
3Asset Admin
AssetsFramework
Jun 17, 2026
Nov 23, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS.
1Sankhya
1Sankhya Om
Jul 9, 2026
Nov 22, 2022
N/A· v4
9.0 CRITICAL· v3
N/A· v2
ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.
1Teacher Record Management System Project
1Teacher Record Management System
Jun 17, 2026
Nov 22, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Record Management System using CodeIgniter 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Subject page.
1Backdropcms
1Backdrop
Jun 17, 2026
Nov 22, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .
1Backdropcms
1Backdrop
Jun 17, 2026
Nov 22, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' content.
1Silverstripe
1Framework
Jun 17, 2026
Nov 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request.
1Muffingroup
1Betheme
Jun 17, 2026
Nov 22, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) in Muffingroup Betheme theme <= 26.6.1 on WordPress.
1Fusiondirectory
1Fusiondirectory
Jul 9, 2026
Nov 22, 2022
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout...Show more
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.Show less
1Mybb
1Mybb
Jun 17, 2026
Nov 22, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings.
1Mybb
1Mybb
Jun 17, 2026
Nov 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow attackers to inject HTML by persuading the user to upload a file with specially crafted name
1Mybb
1Mybb
Jun 17, 2026
Nov 22, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote attackers to inject HTML via user input or stored data
1Maggioli
1Appalti & Contratti
Jun 17, 2026
Nov 21, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in Appalti & Contratti 9.12.2. The web applications are vulnerable to a Reflected Cross-Site Scripting issue. The idPagina parameter is reflected inside the server response without any HTML encodi...Show more
An issue was discovered in Appalti & Contratti 9.12.2. The web applications are vulnerable to a Reflected Cross-Site Scripting issue. The idPagina parameter is reflected inside the server response without any HTML encoding, resulting in XSS when the victim moves the mouse pointer inside the page. As an example, the onmouseenter attribute is not sanitized.Show less