← Back
CWE-79

47,382 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,382)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Feehi
1Feehi Cms
Jun 17, 2026
Jul 28, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.
1Fossil Scm
1Fossil
Jun 17, 2026
Jul 28, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This occurs because the ticket data is stored in a temporary file, and the product does not properly han...Show more
Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This occurs because the ticket data is stored in a temporary file, and the product does not properly handle the absence of this file after Windows Defender has flagged it as malware.Show less
1Kabir M Alhasan
1Student Management System
Jun 17, 2026
Jul 28, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in /nav_bar_action.php of Student Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Chat box.
1Veritas
1Netbackup
Jun 17, 2026
Jul 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
In Veritas NetBackup OpsCenter, a DOM XSS attack can occur. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.
1Visam
1Vbase Web Remote
Jun 17, 2026
Jul 27, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
VISAM VBASE version 11.6.0.6 does not neutralize or incorrectly neutralizes user-controllable input before the data is placed in output used as a public-facing webpage.
1Bxslider Wp Project
1Bxslider Wp
Jun 17, 2026
Jul 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Authenticated (contributor or higher user role) Cross-Site Scripting (XSS) vulnerability in Nico Amarilla's BxSlider WP plugin <= 2.0.0 at WordPress.
1Jenkins
1Lucene Search
Jun 17, 2026
Jul 27, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the 'search' result page, resulting in a reflected cross-site scripting (XSS) vulnerability.
1Jenkins
1Maven Metadata
Jun 17, 2026
Jul 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.2 and earlier does not perform URL validation for the Repository Base URL of List maven artifact versions parameters, resulting in a stored cross-site scriptin...Show more
Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.2 and earlier does not perform URL validation for the Repository Base URL of List maven artifact versions parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Dynamic Extended Choice Parameter
Jun 17, 2026
Jul 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape several fields of Moded Extended Choice parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attacke...Show more
Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape several fields of Moded Extended Choice parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Student Information Management System Project
1Student Information Management System
Jun 17, 2026
Jul 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Sims v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /addNotifyServlet. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injec...Show more
Sims v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /addNotifyServlet. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the notifyInfo parameter.Show less
1Open Xchange
1Ox App Suite
Jun 17, 2026
Jul 27, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.
1Open Xchange
1App Suite
Jun 17, 2026
Jul 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
OX App Suite through 7.10.6 allows XSS by forcing block-wise read.
1Webmin
2Usermin
Webmin
Jun 17, 2026
Jul 27, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message.
1Online Fire Reporting System Project
1Online Fire Reporting System
Jul 9, 2026
Jul 27, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "Contac #" text fi...Show more
A cross-site scripting (XSS) vulnerability in /index.php/?p=report of Online Fire Reporting System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "Contac #" text field.Show less
1Advanced School Management System Project
1Advanced School Management System
Jun 17, 2026
Jul 27, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component ip/school/moudel/update_subject.php. This vulnerability allows attackers to execute arbitrary...Show more
Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component ip/school/moudel/update_subject.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Subject text field.Show less
1Digitus
1Inmailx
Jun 17, 2026
Jul 26, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
InMailX Outlook Plugin < 3.22.0101 is vulnerable to Cross Site Scripting (XSS). InMailX Connection names are not sanitzed in the Outlook tab, which allows a local user or network administrator to execute HTML / Javascrip...Show more
InMailX Outlook Plugin < 3.22.0101 is vulnerable to Cross Site Scripting (XSS). InMailX Connection names are not sanitzed in the Outlook tab, which allows a local user or network administrator to execute HTML / Javascript in the Outlook of users.Show less
1Google
1Chrome
Jun 17, 2026
Jul 26, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Insufficient data validation in Trusted Types in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass trusted types policy via a crafted HTML page.
1Google
1Chrome
Jun 17, 2026
Jul 26, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Insufficient data validation in Blink Editing in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to inject arbitrary scripts or HTML via a crafted HTML page.
1Techvill
1Paymoney
Jun 17, 2026
Jul 26, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Paymoney v3.3 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the first_name and last_name parameters.
1Inoutscripts
1Blockchain Altexchanger
Jun 17, 2026
Jul 26, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Inout Blockchain AltExchanger v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/js.