CWE-79
47,382 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,382)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS configurable apps may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could...Show more |
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript c...Show more |
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary Ja...Show more |
Authenticated stored cross-site scripting (XSS) vulnerability in "Field Server Address" field in INTELBRAS ATA 200 Firmware 74.19.10.21 allows attackers to inject JavaScript code through a crafted payload. |
1Simple And Nice Shopping Cart Script Project 1Simple And Nice Shopping Cart Script Jun 17, 2026 Aug 15, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability has been found in SourceCodester Simple and Nice Shopping Cart Script and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /mkshope/login.php. The manipula...Show more |
1Guest Management System Project 1Guest Management System Jun 17, 2026 Aug 15, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability classified as problematic has been found in SourceCodester Guest Management System. This affects an unknown part of the file myform.php. The manipulation of the argument name leads to cross site scripting...Show more |
1Supsystic 1Digital Publications By Supsystic Jun 17, 2026 Aug 15, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_...Show more |
1Easy Student Results Project 1Easy Student Results Jun 17, 2026 Aug 15, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Easy Student Results WordPress plugin through 2.2.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting |
1Duplicate Page And Post Project 1Duplicate Page And Post Jun 17, 2026 Aug 15, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Duplicate Page and Post WordPress plugin before 2.8 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capabil...Show more |
1Webacetechs 1Contact Form Db Elementor Jun 17, 2026 Aug 15, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The Contact Form DB WordPress plugin before 1.8.0 does not sanitise and escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting |
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the description of a rule node. |
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the title of a rule node. |
A cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "end_date" Parameter |
A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publish_on_time" Parameter. |
A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publish_on_date" Parameter |
A stored cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "start_date" Parameter |
In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/search?action accepts parameters called extra, title, and onload that are partially sanitised and lead to reflected XSS that allows executing arbitrary JavaScript...Show more |
1Apartment Visitors Management System Project 1Apartment Visitors Management System Jun 17, 2026 Aug 11, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability was found in SourceCodester Apartment Visitor Management System. It has been classified as problematic. This affects an unknown part of the file profile.php. The manipulation leads to cross site scripting...Show more |
1Company Website Cms Project 1Company Website Cms Jun 17, 2026 Aug 11, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A vulnerability, which was classified as problematic, has been found in SourceCodester Company Website CMS. This issue affects some unknown processing of the file /dashboard/contact. The manipulation of the argument phon...Show more |
1Library Management System Project 1Library Management System Jun 17, 2026 Aug 11, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability classified as problematic was found in SourceCodester Library Management System. This vulnerability affects unknown code of the file /qr/I/. The manipulation of the argument error leads to cross site scri...Show more |