← Back
CWE-79

47,382 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,382)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mm Wiki Project
1Mm Wiki
Jun 17, 2026
Aug 26, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
mm-wiki v0.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the markdown editor.
1Rsa
1Archer
Jun 17, 2026
Aug 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application use...Show more
Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application. This code is then reflected to the victim and gets executed by the web browser in the context of the vulnerable web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.Show less
1Rsa
1Archer
Jun 17, 2026
Aug 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious code in...Show more
Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious code in the context of the web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.Show less
1Redhat
3Build Of Quarkus
Openshift Application RuntimesSmallrye Health
Jun 17, 2026
Aug 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks.
1Jflyfox
1Jfinal Cms
Jun 17, 2026
Aug 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the post title text field under the publish blog module.
1Ge
1Workstationst
Jun 17, 2026
Aug 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected cross-site scripting (XSS) vulnerability exists in the iHistorian Data Display of WorkstationST (<v07.09.15) could allow an attacker to compromise a victim's browser. WorkstationST is only deployed in specifi...Show more
A reflected cross-site scripting (XSS) vulnerability exists in the iHistorian Data Display of WorkstationST (<v07.09.15) could allow an attacker to compromise a victim's browser. WorkstationST is only deployed in specific, controlled environments rendering attack complexity significantly higher than if the attack were conducted on the software in isolation. WorkstationST v07.09.15 can be found in ControlST v07.09.07 SP8 and greater.Show less
1Claroline
1Claroline
Jun 17, 2026
Aug 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event.
1Claroline
1Claroline
Jun 17, 2026
Aug 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
1Claroline
1Claroline
Jun 17, 2026
Aug 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privileged user. By combining the XSS vulnerability present in several upload forms and a javascript reque...Show more
Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privileged user. By combining the XSS vulnerability present in several upload forms and a javascript request to the present API, it is possible to trigger the creation of a user with administrative rights by opening an SVG file as an administrator user.Show less
1Altn
1Security Gateway For Email Servers
Jun 17, 2026
Aug 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter.
1Altn
1Security Gateway For Email Servers
Jun 17, 2026
Aug 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint.
1Altn
1Security Gateway For Email Servers
Jun 17, 2026
Aug 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to inject malicious tag leads to IFRAME injection.
1Altn
1Security Gateway For Email Servers
Jun 17, 2026
Aug 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint.
1Altn
1Security Gateway For Email Servers
Jun 17, 2026
Aug 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoint.
1Altn
1Security Gateway For Email Servers
Jun 17, 2026
Aug 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint.
1Getkirby
1Kirby
Jun 17, 2025
Aug 24, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web pages.
1Articatech
1Artica Proxy
Jun 17, 2026
Aug 24, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.login.php.
1Exceedone
2Exment
Laravel Admin
Jun 17, 2026
Aug 24, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Stored cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2....Show more
Stored cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote authenticated attacker to inject an arbitrary script.Show less
1Exceedone
2Exment
Laravel Admin
Jun 17, 2026
Aug 24, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Reflected cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2...Show more
Reflected cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows a remote authenticated attacker to inject an arbitrary script.Show less
1Servicenow
1Servicenow
Jun 17, 2026
Aug 23, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.