← Back
CWE-79

47,180 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,180)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Beekeeperstudio
1Beekeeper Studio
Jun 17, 2026
Nov 21, 2022
N/A· v4
9.6 CRITICAL· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error modal container.
1Backdropcms
1Backdrop Cms
Jun 17, 2026
Nov 21, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.
1Kiwitcms
1Kiwi Tcms
Jun 17, 2026
Nov 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history pag...Show more
A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page.Show less
1Password Storage Application Project
1Password Storage Application
Jun 17, 2026
Nov 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Sourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Name, Username, Description and Site Feature parameters.
1Phpgurukul
1Blood Donor Management System
Jun 17, 2026
Nov 21, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature.
1Silverstripe
1Framework
Jun 17, 2026
Nov 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3).
1Wbce
1Wbce Cms
Jun 17, 2026
Nov 21, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field.
1Wbce
1Wbce Cms
Jun 17, 2026
Nov 21, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field.
1Wbce
1Wbce Cms
Jun 17, 2026
Nov 21, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Footer field.
1Wbce
1Wbce Cms
Jun 17, 2026
Nov 21, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Header field.
1Wbce
1Wbce Cms
Jun 17, 2026
Nov 21, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Section Header field.
1Wbce
1Wbce Cms
Jun 17, 2026
Nov 21, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Source field.
1Librenms
1Librenms
Jun 17, 2026
Nov 20, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.
1Librenms
1Librenms
Jun 17, 2026
Nov 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attac...Show more
A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attack that enables an attacker with a low privilege user to execute arbitrary JavaScript in the context of an admin's account.Show less
1Librenms
1Librenms
Jun 17, 2026
Nov 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
1Librenms
1Librenms
Jun 17, 2026
Nov 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
1Librenms
1Librenms
Jun 17, 2026
Nov 20, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.
1Librenms
1Librenms
Jun 17, 2026
Nov 20, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
1Flarum
1Flarum
Jun 17, 2026
Nov 19, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change was made after `v1.5` and was not noticed. This al...Show more
Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change was made after `v1.5` and was not noticed. This allowed an attacker to inject malicious HTML markup using a discussion title input, either by creating a new discussion or renaming one. The XSS attack occurs after a visitor opens the relevant discussion page. All communities running Flarum from `v1.5.0` to `v1.6.1` are impacted. The vulnerability has been fixed and published as flarum/core `v1.6.2`. All communities running Flarum from `v1.5.0` to `v1.6.1` have to upgrade as soon as possible to v1.6.2. There are no known workarounds for this issue.Show less
1Oxilab
1Accordions
Jun 17, 2026
Nov 18, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Multiple Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabilities in Accordions plugin <= 2.0.3 on WordPress via &addons-style-name and &accordions_or_faqs_license_key.