CWE-79
47,383 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,383)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Inoutscripts 1Blockchain Altexchanger Jun 17, 2026 Jul 26, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Inout Blockchain AltExchanger v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/js. |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Jul 26, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog...Show more |
Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles. |
1Openteknik 1Open Source Social Network Jun 17, 2026 Jul 25, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an HTML injection vulnerability via the location parameter at http://ip_address/:port/ossn/home. |
1Westerndigital 8My Cloud Dl2100 Firmware My Cloud Dl4100 FirmwareMy Cloud Ex2100 Firmware+5 moreJun 17, 2026 Jul 25, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Western Digital My Cloud devices are vulnerable to a cross side scripting vulnerability that can allow a malicious user with elevated privileges access to drives being backed up to construct and inject JavaScript payload...Show more |
1Openteknik 1Open Source Social Network Jun 17, 2026 Jul 25, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Group Timeline module. |
In Pandora FMS v7.0NG.761 and below, in the agent creation section, the alias parameter is vulnerable to a Stored Cross Site-Scripting. This vulnerability can be exploited by an attacker with administrator privileges log...Show more |
In Pandora FMS v7.0NG.761 and below, in the file manager section, the dirname parameter is vulnerable to a Stored Cross Site-Scripting. This vulnerability can be exploited by an attacker with administrator privileges log...Show more |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleJun 17, 2026 Jul 25, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a spec...Show more |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleJun 17, 2026 Jul 25, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafte...Show more |
1Openteknik 1Open Source Social Network Jun 17, 2026 Jul 25, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the SitePages module. |
1Openteknik 1Open Source Social Network Jun 17, 2026 Jul 25, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the News Feed module. |
1Openteknik 1Open Source Social Network Jun 17, 2026 Jul 25, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Users Timeline module. |
Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2. |
The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of error messages which contained the parameters in verbatim. |
The package grapesjs before 0.19.5 are vulnerable to Cross-site Scripting (XSS) due to an improper sanitization of the class name in Selector Manager. |
1Markdown It Decorate Project 1Markdown It Decorate Jun 17, 2026 Jul 25, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link. |
1Markdown It Toc Project 1Markdown It Toc Jun 17, 2026 Jul 25, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped. |
1Simple Page Transition Project 1Simple Page Transition Jun 17, 2026 Jul 25, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The Simple Page Transition WordPress plugin through 1.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the un...Show more |
The W-DALIL WordPress plugin through 2.0 does not sanitise and escape some of its fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capab...Show more |