CWE-79
47,190 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,190)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /module/admin_bp/add_application.php. |
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /module/report_event/index.php. |
1Oretnom23 1Food Ordering Management System Jun 17, 2026 Nov 7, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Food Ordering Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /foms/place-order.php. |
1Oretnom23 1Human Resource Management System Jun 17, 2026 Nov 7, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A cross-site scripting (XSS) vulnerability in /hrm/index.php?msg of Human Resource Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. |
Cross-site Scripting (XSS) - DOM in GitHub repository jgraph/drawio prior to 20.5.2. |
1Highlight Focus Project 1Highlight Focus Jun 17, 2026 Nov 7, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Highlight Focus WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilt...Show more |
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2. |
1Splunk 2Splunk Splunk Cloud PlatformJun 17, 2026 Nov 4, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts that can lead to persistent cross-site scripting (XSS) in the object name of a Data Model.
|
1Splunk 2Splunk Splunk Cloud PlatformJun 17, 2026 Nov 4, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON) in a query parameter when output_mode=radio.
|
Saibamen HotelManager v1.2 is vulnerable to Cross Site Scripting (XSS) due to improper sanitization of comment and contact fields. |
The Foundry Blobster service was found to have a cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Foundry to launch attacks against other users. This vulnerability is resolved i...Show more |
A vulnerability in multiple management dashboard pages of Cisco Umbrella could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the Cisco Umbrella dashboard. Thi...Show more |
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based m...Show more |
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39. |
1Stiltsoft 1Handy Macros For Confluence Jun 17, 2026 Nov 4, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability. |
1Splunk 2Splunk Splunk Cloud PlatformJun 17, 2026 Nov 3, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user that holds the “power” Splunk role can store arbitrary scripts that can lead to persistent cross-site scripting (XSS). The vulnerability affects...Show more |
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JumpDEMAND Inc. 4ECPS Web Forms plugin <= 0.2.17 on WordPress. |
CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input...Show more |
CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate u...Show more |
CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user inp...Show more |