CWE-79
47,382 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,382)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 2Engineering Test Management Rational Quality ManagerJun 17, 2026 Aug 29, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 IBM Engineering Test Management 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality poten...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11. |
kirby is a content management system (CMS) that adapts to many different projects and helps you build your own ideal interface. Cross-site scripting (XSS) is a type of vulnerability that allows execution of any kind of J...Show more |
1Anti Malware Security And Brute Force Firewall Project 1Anti Malware Security And Brute Force Firewall Jun 17, 2026 Aug 29, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some parameters before outputting them back in an admin dashboard, leading to Reflected Cross-Site Scripting |
1Nsp Code 1Wp Hide & Security Enhancer Jun 17, 2026 Aug 29, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The WP Hide & Security Enhancer WordPress plugin before 1.8 does not escape a parameter before outputting it back in an attribute of a backend page, leading to a Reflected Cross-Site Scripting |
1Wpovernight 1Woocommerce Pdf Invoices& Packing Slips Jun 17, 2026 Aug 29, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scrip...Show more |
1Nsqua 1Simply Schedule Appointments Jun 17, 2026 Aug 29, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even...Show more |
2Jsoup Netapp4Jsoup Management Services For Element SoftwareManagement Services For Netapp Hci+1 moreJun 17, 2026 Aug 29, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks w...Show more |
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability...Show more |
Cross Site Scripting (XSS) in Admin Panel of Subrion CMS 4.2.1 allows attacker to inject arbitrary code via Login Field |
Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding a crafted payload into the name parameter. |
A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Markdown text box under /blog/post/edit. |
1Fast Food Ordering System Project 1Fast Food Ordering System Jun 17, 2026 Aug 27, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability, which was classified as problematic, has been found in oretnom23 Fast Food Ordering System. This issue affects some unknown processing of the file admin/?page=reports. The manipulation of the argument da...Show more |
1Simple Task Managing System Project 1Simple Task Managing System Jun 17, 2026 Aug 27, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability classified as problematic was found in SourceCodester Simple Task Managing System. This vulnerability affects unknown code. The manipulation of the argument student_add leads to cross site scripting. The...Show more |
1Hashenudara 1Edoc Doctor Appointment System Jun 17, 2026 Aug 26, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Edoc-doctor-appointment-system v1.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability at /patient/settings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via...Show more |
1Hashenudara 1Edoc Doctor Appointment System Jun 17, 2026 Aug 26, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /patient/index.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via...Show more |
IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr...Show more |
A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack...Show more |
The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torren...Show more |
1Online Diagnostic Lab Management System Project 1Online Diagnostic Lab Management System Jun 17, 2026 Aug 26, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 An issue was discovered in Online Diagnostic Lab Management System 1.0. There is a stored XSS vulnerability via firstname, address, middlename, lastname , gender, email, contact parameters. |