CWE-79
47,180 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,180)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Beekeeperstudio 1Beekeeper Studio Jun 17, 2026 Nov 21, 2022 N/A· v4 9.6 CRITICAL· v3 N/A· v2 A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error modal container. |
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content. |
A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history pag...Show more |
1Password Storage Application Project 1Password Storage Application Jun 17, 2026 Nov 21, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Sourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Name, Username, Description and Site Feature parameters. |
1Phpgurukul 1Blood Donor Management System Jun 17, 2026 Nov 21, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature. |
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3). |
A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Loop field. |
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field. |
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Footer field. |
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Header field. |
A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Section Header field. |
A cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Source field. |
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0. |
A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attac...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. |
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. |
Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0. |
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. |
Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change was made after `v1.5` and was not noticed. This al...Show more |
Multiple Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabilities in Accordions plugin <= 2.0.3 on WordPress via &addons-style-name and &accordions_or_faqs_license_key. |