← Back
CWE-79

47,196 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,196)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Themepoints
1Super Testimonials
Jun 17, 2026
Oct 28, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themepoints Testimonials plugin <= 2.6 on WordPress.
1Phpgurukul
1Employee Record Management System
Jun 17, 2026
Oct 28, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Employee Record Management System v 1.2 is vulnerable to Cross Site Scripting (XSS) via editempprofile.php.
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Oct 28, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.
1Johnsoncontrols
1Cevas
Jun 17, 2026
Oct 28, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retrieve data with specially crafted SQL queries.
1Deltaww
1Diaenergie
Jun 17, 2026
Oct 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the InsertReg API.
1Deltaww
1Diaenergie
Jun 17, 2026
Oct 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutShift API.
1Deltaww
1Diaenergie
Jun 17, 2026
Oct 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the SetPF API.
1Deltaww
1Diaenergie
Jun 17, 2026
Oct 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PutLineMessageSetting API.
1Deltaww
1Diaenergie
Jun 17, 2026
Oct 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerability through the PostEnergyType API.
1Softr
1Softr
Jun 17, 2026
Oct 27, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Softr v2.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via the First Name parameter under the Create A New Account module. This vulnerability allows attackers to execute arbitrary web scripts or...Show more
Softr v2.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via the First Name parameter under the Create A New Account module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload.Show less
1Gl Inet
1Goodcloud
Jun 17, 2026
Oct 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected...Show more
Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Company Name and Description text fields.Show less
1Bosch
1Videojet Multi 4000 Firmware
Jun 17, 2026
Oct 27, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Incomplete filtering of JavaScript code in different configuration fields of the web based interface of the VIDEOJET multi 4000 allows an attacker with administrative credentials to store JavaScript code which will be ex...Show more
Incomplete filtering of JavaScript code in different configuration fields of the web based interface of the VIDEOJET multi 4000 allows an attacker with administrative credentials to store JavaScript code which will be executed for all administrators accessing the same configuration option.Show less
1Bosch
1Videojet Multi 4000 Firmware
Jun 17, 2026
Oct 27, 2022
N/A· v4
4.7 MEDIUM· v3
N/A· v2
An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the encoder address can send a crafted link to a user, w...Show more
An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the encoder address can send a crafted link to a user, which will execute JavaScript code in the context of the user.Show less
1Password Storage Application Project
1Password Storage Application
Jul 9, 2026
Oct 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Password Storage Application v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Setup page.
1Simple Online Public Access Catalog Project
1Simple Online Public Access Catalog
Jul 9, 2026
Oct 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in Simple Online Public Access Catalog v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Account Full Name field...Show more
A stored cross-site scripting (XSS) vulnerability in Simple Online Public Access Catalog v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Account Full Name field.Show less
1Train Scheduler App Project
1Train Scheduler App
Jul 9, 2026
Oct 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Multiple stored cross-site scripting (XSS) vulnerabilities in Train Scheduler App v1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Train Code, Train Name, and Destinat...Show more
Multiple stored cross-site scripting (XSS) vulnerabilities in Train Scheduler App v1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Train Code, Train Name, and Destination text fields.Show less
1Oretnom23
1Online Medicine Ordering System
Jun 17, 2026
Oct 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability classified as problematic was found in SourceCodester Online Medicine Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /omos/admin/?page=user/list. The manipulat...Show more
A vulnerability classified as problematic was found in SourceCodester Online Medicine Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /omos/admin/?page=user/list. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-212347.Show less
1Yordam
1Library Automation System
Jun 17, 2026
Oct 27, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Yordam Library Information Document Automation product before version 19.02 has an unauthenticated reflected XSS vulnerability.
1Rubyonrails
1Rails
Jun 17, 2026
Oct 26, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file actionpack/lib/action_dispatch/middleware/templates/routes/_table.html.erb. The manipulation leads to cr...Show more
A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file actionpack/lib/action_dispatch/middleware/templates/routes/_table.html.erb. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The real existence of this vulnerability is still doubted at the moment. The name of the patch is be177e4566747b73ff63fd5f529fab564e475ed4. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-212319. NOTE: Maintainer declares that there isn’t a valid attack vector. The issue was wrongly reported as a security vulnerability by a non-member of the Rails team.Show less
2Debian
Twisted
2Debian Linux
Twisted
Jun 17, 2026
Oct 26, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not match a configured host `twisted.web.vhost.NameVirtualHost` will return a `NoResource` resource whi...Show more
Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not match a configured host `twisted.web.vhost.NameVirtualHost` will return a `NoResource` resource which renders the Host header unescaped into the 404 response allowing HTML and script injection. In practice this should be very difficult to exploit as being able to modify the Host header of a normal HTTP request implies that one is already in a privileged position. This issue was fixed in version 22.10.0rc1. There are no known workarounds.Show less