← Back
CWE-79

47,376 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,376)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pimcore
1Pimcore
Jun 17, 2026
Sep 21, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user. Amongst other things, the attacker can: Perform any action within the application that the...Show more
If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise that user. Amongst other things, the attacker can: Perform any action within the application that the user can perform. View any information that the user is able to view. Modify any information that the user is able to modify. Initiate interactions with other application users, including malicious attacks, that will appear to originate from the initial victim user.Show less
1Sftpgo Project
1Sftpgo
Jun 17, 2026
Sep 20, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient, allowing remote attackers to inject malicious code. This issue is patched...Show more
SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient, allowing remote attackers to inject malicious code. This issue is patched in version 2.3.5. No known workarounds exist.Show less
1Cloudreve
1Cloudreve
Jun 17, 2026
Sep 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to...Show more
Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to privilege escalation.Show less
1Microweber
1Microweber
Jun 17, 2026
Sep 20, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validatio...Show more
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.Show less
1Microweber
1Microweber
Jun 17, 2026
Sep 20, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Code Injection in GitHub repository microweber/microweber prior to 1.3.2.
1Yetiforce
1Yetiforce Customer Relationship Management
Jun 17, 2026
Sep 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
1Yetiforce
1Yetiforce Customer Relationship Management
Jun 17, 2026
Sep 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
1Yetiforce
1Yetiforce Customer Relationship Management
Jun 17, 2026
Sep 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
1Yetiforce
1Yetiforce Customer Relationship Management
Jun 17, 2026
Sep 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3.
1Jeesns
1Jeesns
Jun 17, 2026
Sep 19, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in the /weibo/list component of Jeesns v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
1Valine.js
1Valine
Jun 17, 2026
Sep 19, 2022
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.
1Ucms Project
1Ucms
Jun 17, 2026
Sep 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
UCMS v1.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Import function under the Site Management page.
1Safe
1Fme Server
Jun 17, 2026
Sep 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login...Show more
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login page.Show less
1Nokia
11350 Optical Management System
Jun 17, 2026
Sep 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /oms1350/* endpoints.
1Nokia
11350 Optical Management System
Jun 17, 2026
Sep 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /cgi-bin/R14.2* endpoints.
1Gettext Override Translations Project
1Gettext Override Translations
Jun 17, 2026
Sep 19, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Gettext override translations WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even...Show more
The Gettext override translations WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Diywebmastery
1Slickr Flickr
Jun 17, 2026
Sep 19, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Slickr Flickr WordPress plugin through 2.8.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is...Show more
The Slickr Flickr WordPress plugin through 2.8.1 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Ketchup Restaurant Reservations Project
1Ketchup Restaurant Reservations
Jun 17, 2026
Sep 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not sanitise and escape some of the reservation user inputs, allowing unauthenticated attackers to perform Cross-Site Scripting attacks logged in ad...Show more
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not sanitise and escape some of the reservation user inputs, allowing unauthenticated attackers to perform Cross-Site Scripting attacks logged in admin viewing the malicious reservation madeShow less
1Scroll To Top Project
1Scroll To Top
Jun 17, 2026
Sep 19, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Scroll To Top WordPress plugin before 1.4.1 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capa...Show more
The Scroll To Top WordPress plugin before 1.4.1 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
2Cagewebdesign
Cagewebdev
2Float To Top Button
Float To Top Button
Jun 17, 2026
Sep 19, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Float to Top Button WordPress plugin through 2.3.6 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_ht...Show more
The Float to Top Button WordPress plugin through 2.3.6 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less