← Back
CWE-79

47,376 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,376)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
1Netweaver Enterprise Portal
Jun 17, 2026
Sep 13, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability. KMC servlet is vulnerable to XSS attack. The execution of script...Show more
SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability. KMC servlet is vulnerable to XSS attack. The execution of script content by a victim registered on the portal could compromise the confidentiality and integrity of victim’s web browser session.Show less
1Sap
1Netweaver Application Server Abap
Jun 17, 2026
Sep 13, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Script...Show more
An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Scripting attack. This could lead to information disclosure including stealing authentication information and impersonating the affected user.Show less
1Synel
1Eharmony
Jun 17, 2026
Sep 13, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this input the code.
1Cuppacms
1Cuppacms
Jun 17, 2026
Sep 12, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload inje...Show more
Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Add New Group function.Show less
1Slims
1Senayan Library Management System
Jun 17, 2026
Sep 12, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Search function. This vulnerability allows attackers to execute arbitrary web scripts or HTML vi...Show more
SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Search function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search bar.Show less
1Hotel Management System Project
1Hotel Management System
Jun 17, 2026
Sep 12, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname...Show more
Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname".Show less
1Ark Web
1A Form
Jun 17, 2026
Sep 12, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-site scripting vulnerability in Movable Type plugin A-Form versions prior to 4.1.1 (for Movable Type 7 Series) and versions prior to 3.9.1 (for Movable Type 6 Series) allows a remote unauthenticated attacker to inj...Show more
Cross-site scripting vulnerability in Movable Type plugin A-Form versions prior to 4.1.1 (for Movable Type 7 Series) and versions prior to 3.9.1 (for Movable Type 6 Series) allows a remote unauthenticated attacker to inject an arbitrary script.Show less
1Oretnom23
1Simple Online Book Store System
Jun 17, 2026
Sep 12, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In Simple Online Book Store System 1.0 in /admin_book.php the Title, Author, and Description parameters are vulnerable to Cross Site Scripting(XSS).
1Sysaid
1Help Desk
Jun 17, 2026
Sep 11, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262.
1Sysaid
1Help Desk
Jun 17, 2026
Sep 11, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258.
1Sysaid
1Help Desk
Jun 17, 2026
Sep 11, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241.
1Sysaid
1Help Desk
Jun 17, 2026
Sep 11, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579.
1Inkdrop
1Markdown Nice
Jun 17, 2026
Sep 9, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field.
1Openkm
1Openkm
Jun 17, 2026
Sep 9, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.
1Wso2
1Enterprise Integrator
Jun 17, 2026
Sep 9, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatasource/validateconnection/ajaxprocessor.j...Show more
An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatasource/validateconnection/ajaxprocessor.jsp via the driver parameter. Session hijacking or similar attacks would not be possible.Show less
1Wso2
1Enterprise Integrator
Jun 17, 2026
Sep 9, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/mediation_secure_vault/properties/ajaxprocesso...Show more
An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/mediation_secure_vault/properties/ajaxprocessor.jsp via the name parameter. Session hijacking or similar attacks would not be possible.Show less
1Contact Form By Mega Forms Project
1Contact Form By Mega Forms
Jun 17, 2026
Sep 9, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Authenticated (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Ali Khallad's Contact Form By Mega Forms plugin <= 1.2.4 at WordPress.
1Apasionados
1Export Post Info
Jun 17, 2026
Sep 9, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Apasionados Export Post Info plugin <= 1.1.0 at WordPress.
1Better Delete Revision Project
1Better Delete Revision
Jun 17, 2026
Sep 9, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Galerio & Urda's Better Delete Revision plugin <= 1.6.1 at WordPress.
1Wpchill
1Gallery Photoblocks
Jun 17, 2026
Sep 9, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.