← Back
CWE-79

47,190 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,190)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vmware
1Workspace One Assist
Jun 17, 2026
Nov 9, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javasc...Show more
VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.Show less
1Intelliants
1Subrion Cms
Jun 17, 2026
Nov 9, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in the CMS Field Add page of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tooltip text field.
1Intelliants
1Subrion Cms
Jun 17, 2026
Nov 9, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field defa...Show more
A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field default value text field.Show less
1Csphere
1Clansphere
Jun 17, 2026
Nov 9, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Clansphere CMS v2011.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username parameter.
1Flatcore
1Flatcore Cms
Jun 17, 2026
Nov 9, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in flatCore-CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username text field.
1Shopwind
1Shopwind
Jul 9, 2026
Nov 9, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Shopwind v3.4.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the component /common/library/Page.php.
1Feehi
1Feehicms
Jun 17, 2026
Nov 9, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
FeehiCMS v2.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /web/admin/index.php?r=log%2Fview-layer.
1Canteen Management System Project
1Canteen Management System
Jun 17, 2026
Nov 8, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Canteen Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
1Sap
1Financial Consolidation
Jun 17, 2026
Nov 8, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SAP Financial Consolidation - version 1010, does not sufficiently encode user-controlled input which may allow an unauthenticated attacker to inject a web script via a GET request. On successful exploitation, an attacker...Show more
SAP Financial Consolidation - version 1010, does not sufficiently encode user-controlled input which may allow an unauthenticated attacker to inject a web script via a GET request. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application. Show less
1Sap
1Financial Consolidation
Jun 17, 2026
Nov 8, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to inject malicious script when running a common query in the Web Administration Console. On successful e...Show more
Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to inject malicious script when running a common query in the Web Administration Console. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality, integrity and availability of the application. Show less
1Sap
1Financial Consolidation
Jun 17, 2026
Nov 8, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter current user session. On successful exploitation, the attacker can view or...Show more
Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter current user session. On successful exploitation, the attacker can view or modify information, causing a limited impact on confidentiality and integrity of the application. Show less
1Mitsubishielectric
119Ma Ew85s E Firmware
Ma Ew85s Uk FirmwareMac 507if E Firmware+116 more
Jun 17, 2026
Nov 8, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Ric...Show more
Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch and Air Purifier) allows a remote unauthenticated attacker to execute an malicious script on a user's browser to disclose information, etc. The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability. As for the affected product models/versions, see the Mitsubishi Electric's advisory which is listed in [References] section. Show less
1Slidervilla
1Testimonial Slider
Jun 17, 2026
Nov 8, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) in David Anderson Testimonial Slider plugin <= 1.3.1 on WordPress.
1Webartesanal
1Mantenimiento Web
Jun 17, 2026
Nov 8, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Mantenimiento web plugin <= 0.13 on WordPress.
1Getshortcodes
1Shortcodes Ultimate
Jun 17, 2026
Nov 8, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12.0 on WordPress.
1Wpadvancedads
1Advanced Ads Ad Manager & Adsense
Jun 17, 2026
Nov 8, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Advanced Ads GmbH Advanced Ads – Ad Manager & AdSense plugin <= 1.31.1 on WordPress.
15 Anker
15 Anker Connect
Jun 17, 2026
Nov 8, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. Reflected Cross-Site Scripting (XSS) vulnerability in 5 Anker Connect plugin <= 1.2.6 on WordPress.
1Joomla
1Joomla
Jun 17, 2026
Nov 8, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media.
1Perfexcrm
1Perfex Crm
Jun 17, 2026
Nov 8, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
perfex crm 1.10 is vulnerable to Cross Site Scripting (XSS) via /clients/profile.
1Eyesofnetwork
1Web Interface
Jun 17, 2026
Nov 8, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /lilac/main.php.