← Back
CWE-79

47,203 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,203)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Esri
1Arcgis Server
Jun 17, 2026
Oct 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
There is as reflected cross site scripting issue in Esri ArcGIS Server versions 10.9.1 and below which may allow a remote unauthorized attacker able to convince a user to click on a crafted link which could potentially e...Show more
There is as reflected cross site scripting issue in Esri ArcGIS Server versions 10.9.1 and below which may allow a remote unauthorized attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.Show less
1Algosec
1Fireflow
Jun 17, 2026
Oct 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
AlgoSec – FireFlow Reflected Cross-Site-Scripting (RXSS) A malicious user injects JavaScript code into a parameter called IntersectudRule on the search/result.html page. The malicious user changes the request from POST t...Show more
AlgoSec – FireFlow Reflected Cross-Site-Scripting (RXSS) A malicious user injects JavaScript code into a parameter called IntersectudRule on the search/result.html page. The malicious user changes the request from POST to GET and sends the URL to another user (victim). JavaScript code is executed on the browser of the other user.Show less
1Paessler
1Prtg Network Monitor
Jun 17, 2026
Oct 25, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
PRTG Network Monitor through 22.2.77.2204 does not prevent custom input for a device’s icon, which can be modified to insert arbitrary content into the style tag for that device. When the device page loads, the arbitrary...Show more
PRTG Network Monitor through 22.2.77.2204 does not prevent custom input for a device’s icon, which can be modified to insert arbitrary content into the style tag for that device. When the device page loads, the arbitrary Cascading Style Sheets (CSS) data is inserted into the style tag, loading malicious content. Due to PRTG Network Monitor preventing “characters, and from modern browsers disabling JavaScript support in style tags, this vulnerability could not be escalated into a Cross-Site Scripting vulnerability.Show less
1Apache
1Geode
Jun 17, 2026
Oct 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse web application to view Region entries.
1Bookstackapp
1Bookstack
Jun 17, 2026
Oct 24, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to inject an arbitrary script.
1Ipfire
1Ipfire
Jun 17, 2026
Oct 24, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Multiple stored cross-site scripting vulnerabilities in the web user interface of IPFire versions prior to 2.27 allows a remote authenticated attacker with administrative privilege to inject an arbitrary script.
1Chop Chop
1Pop Up Chop Chop
Jun 17, 2026
Oct 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Auth. Stored Cross-Site Scripting (XSS) in Pop-Up Chop Chop plugin <= 2.1.7 on WordPress.
1Fatcatapps
1Analytics Cat
Jun 17, 2026
Oct 21, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Auth. (admin+) Stored Cross-Site Scripting (XSS) in Fatcat Apps Analytics Cat plugin <= 1.0.9 on WordPress.
1Aethon
1Tug Home Base Server
Jun 17, 2026
Oct 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.
1Aethon
1Tug Home Base Server
Jun 17, 2026
Oct 21, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Oct 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via doctor/view-patient.php, admin/view-patient.php, and view-medhistory.php.
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Oct 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via add-patient.php.
1Simple Exam Reviewer Management System Project
1Simple Exam Reviewer Management System
Jun 17, 2026
Oct 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Simple Exam Reviewer Management System v1.0 is vulnerable to Stored Cross Site Scripting (XSS) via the Exam List.
1Easyvista
1Service Manager
Jul 9, 2026
Oct 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in New equipment page in EasyVista Service Manager 2018.1.181.1 allows remote attackers to run arbitrary code via the notes field.
1Garage Management System Project
1Garage Management System
Jun 17, 2026
Oct 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the categoriesName parameter in createCateg...Show more
A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php.Show less
1Opencats
1Opencats
Jun 17, 2026
Oct 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.
1Opencats
1Opencats
Jun 17, 2026
Oct 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.
1Opencats
1Opencats
Jun 17, 2026
Oct 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.
1Opencats
1Opencats
Jun 17, 2026
Oct 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.
1Opencats
1Opencats
Jun 17, 2026
Oct 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.