← Back
CWE-79

47,294 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,294)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Aethon
1Tug Home Base Server
Jun 17, 2026
Oct 21, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Oct 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via doctor/view-patient.php, admin/view-patient.php, and view-medhistory.php.
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Oct 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via add-patient.php.
1Simple Exam Reviewer Management System Project
1Simple Exam Reviewer Management System
Jun 17, 2026
Oct 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Simple Exam Reviewer Management System v1.0 is vulnerable to Stored Cross Site Scripting (XSS) via the Exam List.
1Easyvista
1Service Manager
Jul 9, 2026
Oct 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in New equipment page in EasyVista Service Manager 2018.1.181.1 allows remote attackers to run arbitrary code via the notes field.
1Garage Management System Project
1Garage Management System
Jun 17, 2026
Oct 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the categoriesName parameter in createCateg...Show more
A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php.Show less
1Opencats
1Opencats
Jun 17, 2026
Oct 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the email parameter in the Check Email function.
1Opencats
1Opencats
Jun 17, 2026
Oct 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile component.
1Opencats
1Opencats
Jun 17, 2026
Oct 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback component.
1Opencats
1Opencats
Jun 17, 2026
Oct 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage parameter.
1Opencats
1Opencats
Jun 17, 2026
Oct 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parameter.
1Jenkins
1Custom Checkbox Parameter
Jun 17, 2026
Oct 19, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins Custom Checkbox Parameter Plugin 1.4 and earlier does not escape the name and description of Custom Checkbox Parameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) v...Show more
Jenkins Custom Checkbox Parameter Plugin 1.4 and earlier does not escape the name and description of Custom Checkbox Parameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Contrast Continuous Application Security
Jun 17, 2026
Oct 19, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report, resulting in a stored cross-site scripting (XSS) vulnerability exp...Show more
Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control or modify Contrast service API responses.Show less
1Jenkins
1Pipeline\
Jun 17, 2026
Oct 19, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vuln...Show more
Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines.Show less
1Rukovoditel
1Rukovoditel
Jun 17, 2026
Oct 19, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name paramete...Show more
A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.Show less
1Phpmyfaq
1Phpmyfaq
Jun 17, 2026
Oct 19, 2022
N/A· v4
8.4 HIGH· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-alpha.
1Apache
1Isis
Jun 17, 2026
Oct 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user coul...Show more
Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this would be executed. As of this release, the inputted strings are properly escaped when rendered.Show less
1Liferay
2Dxp
Liferay Portal
Jul 9, 2026
Oct 19, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into...Show more
A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the description field of uploaded svg file.Show less
1Liferay
2Dxp
Liferay Portal
Jul 9, 2026
Oct 18, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update 6, and 7.4 before update 17 allows remote attackers to inject arbitrary...Show more
A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 before update 6, and 7.4 before update 17 allows remote attackers to inject arbitrary web script or HTML.Show less
1Liferay
2Dxp
Liferay Portal
Jul 9, 2026
Oct 18, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote a...Show more
A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7.3.2 through 7.4.3.14, and Liferay DXP 7.3 before update 6, and 7.4 before update 15 allows remote attackers to inject arbitrary web script or HTML via the (1) name, or (2) namespace parameter.Show less