← Back
CWE-79

47,383 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,383)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Social Media Share Buttons Project
1Social Media Share Buttons
Jun 17, 2026
Jul 20, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in René Hermenau's Social Media Share Buttons plugin <= 3.8.1 at WordPress.
1Blogifier
1Blogifier
Jun 17, 2026
Jul 20, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Blogifier v3.0 was discovered to contain an arbitrary file upload vulnerability at /api/storage/upload/PostImage. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted file.
1Wavlink
1Wn533a8 Firmware
Jun 17, 2026
Jul 20, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter.
1Micodus
1Mv720 Firmware
Jun 17, 2026
Jul 20, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The main MiCODUS MV720 GPS tracker web server has a reflected cross-site scripting vulnerability that could allow an attacker to gain control by tricking a user into making a request.
1Dnnsoftware
1Dotnetnuke
Jun 17, 2026
Jul 20, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.
1Dw
1Megapix Firmware
Jun 17, 2026
Jul 19, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a cross-site scripting (XSS) vulnerability via the component bia_oneshot.cgi.
1Vestacp
1Vesta Control Panel
Jun 17, 2026
Jul 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1/upload/UploadHandler.php.
1Vestacp
1Vesta Control Panel
Jun 17, 2026
Jul 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function at /web/api/v1/upload/UploadHandler.php.
1Vestacp
1Vesta Control Panel
Jun 17, 2026
Jul 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function at /web/api/v1/upload/UploadHandler.php.
1Vestacp
1Vesta Control Panel
Jun 17, 2026
Jul 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1/upload/UploadHandler.php.
1Ibm
2Partner Engagement Manager
Partner Engagement Manager On Cloud/saas
Jun 17, 2026
Jul 19, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended f...Show more
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 223127.Show less
1Hcltech
1Bigfix Platform
Jun 17, 2026
Jul 19, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
1Fortinet
1Fortiedr
Jun 17, 2026
Jul 19, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiEDR version 5.1.0, 5.0.0 through 5.0.3 Patch 6 and 4.0.0 allows a remote authenticated attacker to perform a reflect...Show more
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiEDR version 5.1.0, 5.0.0 through 5.0.3 Patch 6 and 4.0.0 allows a remote authenticated attacker to perform a reflected cross site scripting attack (XSS) by injecting malicious payload into the Management Console via various endpoints.Show less
1Fortinet
1Fortios
Jun 17, 2026
Jul 18, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perfor...Show more
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) attack in the captive portal authentication replacement page.Show less
1Ibm
1Engineering Requirements Quality Assistant On Premises
Jun 17, 2026
Jul 18, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 203440.Show less
1Ibm
1Engineering Requirements Quality Assistant On Premises
Jun 17, 2026
Jul 18, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 203310.Show less
1W3eden
1Download Manager
Jun 17, 2026
Jul 18, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping...Show more
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level permissions and above to inject arbitrary web scripts on the file's page that will execute whenever an administrator accesses the editor area for the injected file page.Show less
1Fortinet
1Fortiauthenticator Agent For Microsoft Outlook Web Access
Jun 17, 2026
Jul 18, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via c...Show more
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.Show less
1Dsk
1Dsknet
Jun 17, 2026
Jul 18, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The new menu option within the general Parameters page is vulnerable to stored XSS. The attacker can create a menu option, make it visible to every applica...Show more
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The new menu option within the general Parameters page is vulnerable to stored XSS. The attacker can create a menu option, make it visible to every application user, and conduct session hijacking, account takeover, or malicious code delivery, with the final goal of achieving client-side code execution.Show less
1Monitoringsoft
1Softguard Web
Jun 17, 2026
Jul 17, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
SoftGuard Web (SGW) before 5.1.5 allows HTML injection.