← Back
CWE-79

47,365 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,365)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Simple Task Managing System Project
1Simple Task Managing System
Jul 9, 2026
Sep 21, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newTask.php. This vulnerability allows attackers to execute arbitrary web scripts or...Show more
SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newTask.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the shortName parameter.Show less
1Tibco
1Ebx Add Ons
Jun 17, 2026
Sep 21, 2022
N/A· v4
9.0 CRITICAL· v3
N/A· v2
The Web Server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on t...Show more
The Web Server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 5.4.1 and below.Show less
1Tibco
1Ebx
Jun 17, 2026
Sep 21, 2022
N/A· v4
9.0 CRITICAL· v3
N/A· v2
The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affec...Show more
The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 6.0.0 through 6.0.8.Show less
1Jenkins
1Walti
Jun 17, 2026
Sep 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide malicious API resp...Show more
Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide malicious API responses from Walti.Show less
1Jenkins
1Dotci
Jun 17, 2026
Sep 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerabili...Show more
Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerability.Show less
1Jenkins
1Ns Nd Integration Performance Publisher
Jun 17, 2026
Sep 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud Test build step, resulting in a stored cross-site scripting (XSS) vulner...Show more
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud Test build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Anchore Container Image Scanner
Jun 17, 2026
Sep 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able t...Show more
Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control API responses by Anchore engine.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Sep 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploita...Show more
Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this component.Show less
1Craftcms
1Craft Cms
Jun 17, 2026
Sep 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
1Pimcore
1Pimcore
Jun 17, 2026
Sep 21, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user. Amongst other things, the attacker can: Perform any action within the application that the...Show more
If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user. Amongst other things, the attacker can: Perform any action within the application that the user can perform. View any information that the user is able to view. Modify any information that the user is able to modify. Initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user.Show less
1Sftpgo Project
1Sftpgo
Jun 17, 2026
Sep 20, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient, allowing remote attackers to inject malicious code. This issue is patched...Show more
SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient, allowing remote attackers to inject malicious code. This issue is patched in version 2.3.5. No known workarounds exist.Show less
1Cloudreve
1Cloudreve
Jun 17, 2026
Sep 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to...Show more
Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to privilege escalation.Show less
1Microweber
1Microweber
Jun 17, 2026
Sep 20, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validatio...Show more
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.Show less
1Microweber
1Microweber
Jun 17, 2026
Sep 20, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Code Injection in GitHub repository microweber/microweber prior to 1.3.2.
1Yetiforce
1Yetiforce Customer Relationship Management
Jun 17, 2026
Sep 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
1Yetiforce
1Yetiforce Customer Relationship Management
Jun 17, 2026
Sep 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
1Yetiforce
1Yetiforce Customer Relationship Management
Jun 17, 2026
Sep 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
1Yetiforce
1Yetiforce Customer Relationship Management
Jun 17, 2026
Sep 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3.
1Jeesns
1Jeesns
Jun 17, 2026
Sep 19, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in the /weibo/list component of Jeesns v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
1Valine.js
1Valine
Jun 17, 2026
Sep 19, 2022
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.