← Back
CWE-79

47,382 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,382)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Ofbiz
Jun 17, 2026
Sep 2, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.05, and earlier versions, by leveraging a vulnerability in Birt (https:...Show more
Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. In Apache OFBiz release 18.12.05, and earlier versions, by leveraging a vulnerability in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142), an unauthenticated malicious user could perform a stored XSS attack in order to inject a malicious payload and execute it using the stored XSS.Show less
1Miniblog.core Project
1Miniblog.core
Jun 17, 2026
Sep 2, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Miniblog.Core v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blog/edit. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload inje...Show more
Miniblog.Core v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blog/edit. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Excerpt field.Show less
1Garage Management System Project
1Garage Management System
Jun 17, 2026
Sep 2, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Garage Management System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the brand_name parameter at /brand.php.
1Blogengine
1Blogengine.net
Jun 17, 2026
Sep 2, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/api/posts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted...Show more
BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/api/posts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.Show less
1Redhat
1Single Sign On
Jun 17, 2026
Sep 1, 2022
N/A· v4
3.8 LOW· v3
N/A· v2
A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console, abusing the defaul...Show more
A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console, abusing the default roles functionality.Show less
1Dedecms
1Dedecms
Jun 17, 2026
Sep 1, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/co_do.php via the dopost, rpok, and aid parameters.
1Callrail
1Callrail Phone Call Tracking
Jun 17, 2026
Sep 1, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in CallRail, Inc. CallRail Phone Call Tracking plugin <= 0.4.9 at WordPress.
1Easy Org Chart Project
1Easy Org Chart
Jun 17, 2026
Sep 1, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Easy Org Chart plugin <= 3.1 at WordPress.
1Weave.works
1Gitops
Jun 17, 2026
Sep 1, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Weave GitOps Enterprise before 0.9.0-rc.5 has a cross-site scripting (XSS) bug allowing a malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's pe...Show more
Weave GitOps Enterprise before 0.9.0-rc.5 has a cross-site scripting (XSS) bug allowing a malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permission. The exposure appears in Weave GitOps Enterprise UI via a GitopsCluster dashboard link. An annotation can be added to a GitopsCluster custom resource.Show less
1Rosariosis
1Rosariosis
Jun 17, 2026
Sep 1, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 8.9.3.
1Doctor's Appointment System Project
1Doctor's Appointment System
Jun 17, 2026
Aug 31, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Doctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads to takeover the administrator account by stealing the cookie via XSS.
1Piwigo
1Piwigo
Jun 17, 2026
Aug 31, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Piwigo 12.3.0 is vulnerable to Cross Site Scripting (XSS) via /search/1940/created-monthly-list.
1Microfocus
1Arcsight Logger
Jun 17, 2026
Aug 31, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects:...Show more
Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exploited resulting in Information Disclosure, or Self Cross-Site Scripting (XSS). This issue affects: Micro Focus ArcSight Logger versions prior to v7.2.2 version and prior versions.Show less
1Picuploader Project
1Picuploader
Jun 17, 2026
Aug 30, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
PicUploader v2.6.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /master/index.php.
1Cobub
1Razor
Jun 17, 2026
Aug 30, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Razor v0.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the function uploadchannel().
1Librenms
1Librenms
Jun 17, 2026
Aug 30, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php.
1Librenms
1Librenms
Jun 17, 2026
Aug 30, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php.
1Library Management System Project
1Library Management System
Jun 17, 2026
Aug 30, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Library Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /librarian/edit_book_details.php.
1Dell
1Emc Data Protection Advisor
Jun 17, 2026
Aug 30, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Dell EMC Data Protection Advisor versions 19.6 and earlier, contains a Stored Cross Site Scripting, an attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes i...Show more
Dell EMC Data Protection Advisor versions 19.6 and earlier, contains a Stored Cross Site Scripting, an attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.Show less
1X Data Spreadsheet Project
1X Data Spreadsheet
Jun 17, 2026
Aug 30, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
All versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of values inserted into the cells.