CWE-79
47,364 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,364)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when th...Show more |
The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capab...Show more |
1Adobe 2Commerce Magento Open SourceJun 17, 2026 Oct 14, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-...Show more |
1Oretnom23 1Online Birth Certificate Management System Jun 17, 2026 Oct 14, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability. |
1Oretnom23 1Online Birth Certificate Management System Jun 17, 2026 Oct 14, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Online Birth Certificate Management System version 1.0 suffers from a persistent Cross Site Scripting (XSS) vulnerability. |
1Projectworlds 1Online Examination System Jun 17, 2026 Oct 14, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Online Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php. |
Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3. |
1Sanitization Management System Project 1Sanitization Management System Jun 17, 2026 Oct 14, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability was found in SourceCodester Sanitization Management System. It has been classified as problematic. Affected is an unknown function of the file /php-sms/admin/. The manipulation of the argument page leads...Show more |
1Oretnom23 1Human Resource Management System Jun 17, 2026 Oct 14, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability was found in Human Resource Management System 1.0. It has been classified as problematic. This affects an unknown part of the component Leave Handler. The manipulation of the argument Reason leads to cros...Show more |
1Oretnom23 1Human Resource Management System Jun 17, 2026 Oct 14, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been classified as problematic. Affected is an unknown function of the component Master List. The manipulation of the argument city...Show more |
OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php. |
Knowage is an open source suite for modern business analytics alternative over big data systems. KnowageLabs / Knowage-Server starting with the 6.x branch and prior to versions 7.4.22, 8.0.9, and 8.1.0 is vulnerable to c...Show more |
A cross-site scripting (XSS) vulnerability in MQTTRoute v3.3 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the dashboard name text field. |
Boodskap IoT Platform v4.4.9-02 contains a cross-site scripting (XSS) vulnerability. |
1Resiot 1Iot Platform And Lorawan Network Server Jun 17, 2026 Oct 13, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Multiple Cross Site Scripting (XSS) vulnerabilities in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via the form fields. |
1Oretnom23 1Human Resource Management System Jun 17, 2026 Oct 13, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability, which was classified as problematic, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the component Add Employee Handler. The manipulat...Show more |
RPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function. |
A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experience Platform 7.3.10 SP3 allows remote attackers to inject arbitrary JS script or HTML into the name fi...Show more |
In Zimbra Collaboration Suite (ZCS) 8.8.15, at the URL /h/calendar, one can trigger XSS by adding JavaScript code to the view parameter and changing the value of the uncheck parameter to a string (instead of default valu...Show more |
In Zimbra Collaboration Suite (ZCS) 8.8.15, /h/search?action=voicemail&action=listen accepts a phone parameter that is vulnerable to Reflected XSS. This allows executing arbitrary JavaScript on the victim's machine. |