CWE-79
47,376 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,376)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability. KMC servlet is vulnerable to XSS attack. The execution of script...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Sep 13, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Script...Show more |
insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this input the code. |
Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload inje...Show more |
1Slims 1Senayan Library Management System Jun 17, 2026 Sep 12, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Search function. This vulnerability allows attackers to execute arbitrary web scripts or HTML vi...Show more |
1Hotel Management System Project 1Hotel Management System Jun 17, 2026 Sep 12, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote attackers to inject arbitrary web script or HTML via multiple parameters such as "fullname...Show more |
Cross-site scripting vulnerability in Movable Type plugin A-Form versions prior to 4.1.1 (for Movable Type 7 Series) and versions prior to 3.9.1 (for Movable Type 6 Series) allows a remote unauthenticated attacker to inj...Show more |
1Oretnom23 1Simple Online Book Store System Jun 17, 2026 Sep 12, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 In Simple Online Book Store System 1.0 in /admin_book.php the Title, Author, and Description parameters are vulnerable to Cross Site Scripting(XSS). |
SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262. |
SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258. |
SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241. |
SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579. |
A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field. |
OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element. |
An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/ndatasource/validateconnection/ajaxprocessor.j...Show more |
An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in the Management Console under /carbon/mediation_secure_vault/properties/ajaxprocesso...Show more |
1Contact Form By Mega Forms Project 1Contact Form By Mega Forms Jun 17, 2026 Sep 9, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Authenticated (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Ali Khallad's Contact Form By Mega Forms plugin <= 1.2.4 at WordPress. |
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Apasionados Export Post Info plugin <= 1.1.0 at WordPress. |
1Better Delete Revision Project 1Better Delete Revision Jun 17, 2026 Sep 9, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Galerio & Urda's Better Delete Revision plugin <= 1.6.1 at WordPress. |
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress. |