← Back
CWE-79

47,364 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,364)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mekshq
1Meks Easy Social Share
Jun 17, 2026
Oct 17, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when th...Show more
The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Themeum
1Tutor Lms
Jun 17, 2026
Oct 17, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capab...Show more
The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Adobe
2Commerce
Magento Open Source
Jun 17, 2026
Oct 14, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-...Show more
Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.Show less
1Oretnom23
1Online Birth Certificate Management System
Jun 17, 2026
Oct 14, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.
1Oretnom23
1Online Birth Certificate Management System
Jun 17, 2026
Oct 14, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Online Birth Certificate Management System version 1.0 suffers from a persistent Cross Site Scripting (XSS) vulnerability.
1Projectworlds
1Online Examination System
Jun 17, 2026
Oct 14, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Online Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php.
1Never5
1Related Posts
Jun 17, 2026
Oct 14, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3.
1Sanitization Management System Project
1Sanitization Management System
Jun 17, 2026
Oct 14, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability was found in SourceCodester Sanitization Management System. It has been classified as problematic. Affected is an unknown function of the file /php-sms/admin/. The manipulation of the argument page leads...Show more
A vulnerability was found in SourceCodester Sanitization Management System. It has been classified as problematic. Affected is an unknown function of the file /php-sms/admin/. The manipulation of the argument page leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210840.Show less
1Oretnom23
1Human Resource Management System
Jun 17, 2026
Oct 14, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability was found in Human Resource Management System 1.0. It has been classified as problematic. This affects an unknown part of the component Leave Handler. The manipulation of the argument Reason leads to cros...Show more
A vulnerability was found in Human Resource Management System 1.0. It has been classified as problematic. This affects an unknown part of the component Leave Handler. The manipulation of the argument Reason leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-210831.Show less
1Oretnom23
1Human Resource Management System
Jun 17, 2026
Oct 14, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been classified as problematic. Affected is an unknown function of the component Master List. The manipulation of the argument city...Show more
A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been classified as problematic. Affected is an unknown function of the component Master List. The manipulation of the argument city/state/country/position leads to cross site scripting. It is possible to launch the attack remotely. VDB-210786 is the identifier assigned to this vulnerability.Show less
1Ocomon Project
1Ocomon
Jun 17, 2026
Oct 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php.
1Eng
1Knowage
Jun 17, 2026
Oct 13, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Knowage is an open source suite for modern business analytics alternative over big data systems. KnowageLabs / Knowage-Server starting with the 6.x branch and prior to versions 7.4.22, 8.0.9, and 8.1.0 is vulnerable to c...Show more
Knowage is an open source suite for modern business analytics alternative over big data systems. KnowageLabs / Knowage-Server starting with the 6.x branch and prior to versions 7.4.22, 8.0.9, and 8.1.0 is vulnerable to cross-site scripting because the `XSSRequestWrapper::stripXSS` method can be bypassed. Versions 7.4.22, 8.0.9, and 8.1.0 contain patches for this issue. There are no known workarounds.Show less
1Bevywise
1Mqttroute
Jun 17, 2026
Oct 13, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in MQTTRoute v3.3 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the dashboard name text field.
1Boodskap
1Iot Platform
Jun 17, 2026
Oct 13, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Boodskap IoT Platform v4.4.9-02 contains a cross-site scripting (XSS) vulnerability.
1Resiot
1Iot Platform And Lorawan Network Server
Jun 17, 2026
Oct 13, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Multiple Cross Site Scripting (XSS) vulnerabilities in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via the form fields.
1Oretnom23
1Human Resource Management System
Jun 17, 2026
Oct 13, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability, which was classified as problematic, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the component Add Employee Handler. The manipulat...Show more
A vulnerability, which was classified as problematic, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the component Add Employee Handler. The manipulation of the argument First Name/Middle Name/Last Name leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-210773 was assigned to this vulnerability.Show less
1Rpcms
1Rpcms
Jun 17, 2026
Oct 13, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
RPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function.
1Liferay
2Dxp
Liferay Portal
Jul 9, 2026
Oct 13, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name fi...Show more
A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name field of newly created topic.Show less
1Zimbra
1Collaboration
Jun 17, 2026
Oct 12, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In Zimbra Collaboration Suite (ZCS) 8.8.15, at the URL /h/calendar, one can trigger XSS by adding JavaScript code to the view parameter and changing the value of the uncheck parameter to a string (instead of default valu...Show more
In Zimbra Collaboration Suite (ZCS) 8.8.15, at the URL /h/calendar, one can trigger XSS by adding JavaScript code to the view parameter and changing the value of the uncheck parameter to a string (instead of default value of 10).Show less
1Zimbra
1Collaboration
Jun 17, 2026
Oct 12, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In Zimbra Collaboration Suite (ZCS) 8.8.15, /h/search?action=voicemail&action=listen accepts a phone parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine.