← Back
CWE-79

47,294 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,294)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ocomon Project
1Ocomon
Jun 17, 2026
Oct 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php.
1Eng
1Knowage
Jun 17, 2026
Oct 13, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Knowage is an open source suite for modern business analytics alternative over big data systems. KnowageLabs / Knowage-Server starting with the 6.x branch and prior to versions 7.4.22, 8.0.9, and 8.1.0 is vulnerable to c...Show more
Knowage is an open source suite for modern business analytics alternative over big data systems. KnowageLabs / Knowage-Server starting with the 6.x branch and prior to versions 7.4.22, 8.0.9, and 8.1.0 is vulnerable to cross-site scripting because the `XSSRequestWrapper::stripXSS` method can be bypassed. Versions 7.4.22, 8.0.9, and 8.1.0 contain patches for this issue. There are no known workarounds.Show less
1Bevywise
1Mqttroute
Jun 17, 2026
Oct 13, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in MQTTRoute v3.3 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the dashboard name text field.
1Boodskap
1Iot Platform
Jun 17, 2026
Oct 13, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Boodskap IoT Platform v4.4.9-02 contains a cross-site scripting (XSS) vulnerability.
1Resiot
1Iot Platform And Lorawan Network Server
Jun 17, 2026
Oct 13, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Multiple Cross Site Scripting (XSS) vulnerabilities in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via the form fields.
1Oretnom23
1Human Resource Management System
Jun 17, 2026
Oct 13, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability, which was classified as problematic, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the component Add Employee Handler. The manipulat...Show more
A vulnerability, which was classified as problematic, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the component Add Employee Handler. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-210773 was assigned to this vulnerability.Show less
1Rpcms
1Rpcms
Jun 17, 2026
Oct 13, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
RPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function.
1Liferay
2Dxp
Liferay Portal
Jul 9, 2026
Oct 13, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name fi...Show more
A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.Show less
1Zimbra
1Collaboration
Jun 17, 2026
Oct 12, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In Zimbra Collaboration Suite (ZCS) 8.8.15, at the URL /h/calendar, one can trigger XSS by adding JavaScript code to the view parameter and changing the value of the uncheck parameter to a string (instead of default valu...Show more
In Zimbra Collaboration Suite (ZCS) 8.8.15, at the URL /h/calendar, one can trigger XSS by adding JavaScript code to the view parameter and changing the value of the uncheck parameter to a string (instead of default value of 10).Show less
1Zimbra
1Collaboration
Jun 17, 2026
Oct 12, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In Zimbra Collaboration Suite (ZCS) 8.8.15, /h/search?action=voicemail&action=listen accepts a phone parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.
1Zimbra
1Collaboration
Jun 17, 2026
Oct 12, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/compose accepts an attachUrl parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.
1Zimbra
1Collaboration
Jun 17, 2026
Oct 12, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via the onerror attribute of an IMG element, leading to information disclosure.
1Vanderbilt
1Redcap
Jun 17, 2026
Oct 12, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted CSV file will, when uploaded, trigger arbitrary JavaScript code execution.
1Puppycms
1Puppycms
Jun 17, 2026
Oct 12, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It i...Show more
A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-210699.Show less
1Progress
1Whatsup Gold
Jun 17, 2026
Oct 12, 2022
N/A· v4
9.6 CRITICAL· v3
N/A· v2
In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.
1Jgraph
1Mxgraph
Jul 9, 2026
Oct 12, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.
1Sap
1Businessobjects Business Intelligence
Jun 17, 2026
Oct 11, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-controlled inputs when OLAP connections are created and edited in the Central Mana...Show more
SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-controlled inputs when OLAP connections are created and edited in the Central Management Console. On successful exploitation, there could be a limited impact on confidentiality and integrity of the application. Show less
1Sap
1Businessobjects Business Intelligence
Jun 17, 2026
Oct 11, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SAP BusinessObjects BI LaunchPad - versions 420, 430, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the network. On successf...Show more
SAP BusinessObjects BI LaunchPad - versions 420, 430, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.Show less
1Sap
1Enable Now
Jun 17, 2026
Oct 11, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The application SAP Enable Now does not sufficiently encode user-controlled inputs over the network before it is placed in the output being served to other users, thereby expanding the attack scope, resulting in Stored C...Show more
The application SAP Enable Now does not sufficiently encode user-controlled inputs over the network before it is placed in the output being served to other users, thereby expanding the attack scope, resulting in Stored Cross-Site Scripting (XSS) vulnerability leading to limited impact on Confidentiality, Integrity and Availability.Show less
1Sap
1Data Services
Jun 17, 2026
Oct 11, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SAP Data Services Management allows an attacker to copy the data from a request and echoed into the application's immediate response, it will lead to a Cross-Site Scripting vulnerability. The attacker would have to log i...Show more
SAP Data Services Management allows an attacker to copy the data from a request and echoed into the application's immediate response, it will lead to a Cross-Site Scripting vulnerability. The attacker would have to log in to the management console to perform such as an attack, only few of the pages are vulnerable in the DS management console.Show less