← Back
CWE-79

47,365 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,365)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Comment Guestbook Project
1Comment Guestbook
Jun 17, 2026
Sep 30, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at WordPress.
1Canon
1Medical Vitrea View
Jun 17, 2026
Sep 30, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitre...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers to inject arbitrary web script or HTML via (1) the input after the error subdirectory to the /vitrea-view/error/ subdirectory, or the (2) groupID, (3) offset, or (4) limit parameter to an Administrative Panel (Group and Users) page. There is a risk of an attacker retrieving patient information.Show less
1Dgiotcloud
1Dgiot
Jun 17, 2026
Sep 29, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
DGIOT Lightweight industrial IoT v4.5.4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
1Keking
1Kkfileview
Jun 17, 2026
Sep 29, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
kkFileView v4.1.0 is vulnerable to Cross Site Scripting (XSS) via the parameter 'errorMsg.'
1Dutchcoders
1Transfer.sh
Jun 17, 2026
Sep 29, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
dutchcoders Transfer.sh 1.4.0 is vulnerable to Cross Site Scripting (XSS).
1Feehi
1Feehicms
Jun 17, 2026
Sep 29, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Single Page module.
1Inventree Project
1Inventree
Jun 17, 2026
Sep 29, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3.
1Trudesk Project
1Trudesk
Jun 17, 2026
Sep 29, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capable of executing a malicious javascript code in web page
1Glfusion
1Glfusion
Jun 17, 2026
Sep 29, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
glFusion CMS v1.7.9 is affected by a reflected Cross Site Scripting (XSS) vulnerability. The value of the title request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotatio...Show more
glFusion CMS v1.7.9 is affected by a reflected Cross Site Scripting (XSS) vulnerability. The value of the title request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. This input was echoed unmodified in the application's response.Show less
1Mediawiki
1Mediawiki
Jun 17, 2026
Sep 29, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
An issue was discovered in the Growth extension in MediaWiki through 1.36.2. Any admin can add arbitrary JavaScript code to the Newcomer home page footer, which can be executed by viewers with zero edits.
1Mediawiki
1Mediawiki
Jun 17, 2026
Sep 29, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An issue was discovered in the Growth extension in MediaWiki through 1.36.2. On any Wiki with the Mentor Dashboard feature enabled, users can login with a mentor account and trigger an XSS payload (such as alert) via Gro...Show more
An issue was discovered in the Growth extension in MediaWiki through 1.36.2. On any Wiki with the Mentor Dashboard feature enabled, users can login with a mentor account and trigger an XSS payload (such as alert) via Growthexperiments-mentor-dashboard-mentee-overview-no-js-fallback.Show less
1Mediawiki
1Mediawiki
Jun 17, 2026
Sep 29, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in the GlobalWatchlist extension in MediaWiki through 1.36.2. The rev-deleted-user and ntimes messages were not properly escaped and allowed for users to inject HTML and JavaScript.
1Mediawiki
1Mediawiki
Jun 17, 2026
Sep 29, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An issue was discovered in SecurePoll in the Growth extension in MediaWiki through 1.36.2. Simple polls allow users to create alerts by changing their User-Agent HTTP header and submitting a vote.
1Zyxel
1Cloudcnm Secumanager
Jun 17, 2026
Sep 29, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows live/CPEManager/AXCampaignManager/handle_campaign_script_link?script_name= XSS.
1Ibm
1Rational Change
Nov 21, 2024
Sep 29, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
IBM Rational Change 5.3 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using the SUPP_TEMPLATE_FLAG parameter in a speciall...Show more
IBM Rational Change 5.3 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using the SUPP_TEMPLATE_FLAG parameter in a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.Show less
1Ovirt
1Ovirt Engine
Jun 17, 2026
Sep 28, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize the entry, allowing the vulnerability to trigger on the Windows Servic...Show more
An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_description" fails to sanitize the entry, allowing the vulnerability to trigger on the Windows Service Accounts home pages.Show less
1Oretnom23
1Expense Management System
Jun 17, 2026
Sep 28, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored Cross-Site Scripting (XSS) vulnerability exists in version 1.0 of the Expense Management System application that allows for arbitrary execution of JavaScript commands through index.php.
1Ibm
1Jazz For Service Management
Jun 17, 2026
Sep 28, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM Jazz for Service Management is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more
IBM Jazz for Service Management is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 231381.Show less
1Ibm
1Application Gateway
Jun 17, 2026
Sep 28, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials...Show more
IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 221965.Show less
1Etaplighting
1Etap Safety Manager
Jun 17, 2026
Sep 28, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
ETAP Lighting International NV ETAP Safety Manager 1.0.0.32 is vulnerable to Cross Site Scripting (XSS). Input passed to the GET parameter 'action' is not properly sanitized before being returned to the user. This can be...Show more
ETAP Lighting International NV ETAP Safety Manager 1.0.0.32 is vulnerable to Cross Site Scripting (XSS). Input passed to the GET parameter 'action' is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML/JS code in a user's browser session in context of an affected site.Show less