← Back
CWE-79

47,383 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,383)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Multi Restaurant Table Reservation System Project
1Multi Restaurant Table Reservation System
Jun 17, 2026
Jul 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Area(food_type) field to /dashboard/menu-list.php.
1Multi Restaurant Table Reservation System Project
1Multi Restaurant Table Reservation System
Jun 17, 2026
Jul 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Made field to /dashboard/menu-list.php.
1Multi Restaurant Table Reservation System Project
1Multi Restaurant Table Reservation System
Jun 17, 2026
Jul 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Item Name field to /dashboard/menu-list.php.
1Multi Restaurant Table Reservation System Project
1Multi Restaurant Table Reservation System
Jun 17, 2026
Jul 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Table Name field to /dashboard/table-list.php.
1Multi Restaurant Table Reservation System Project
1Multi Restaurant Table Reservation System
Jun 17, 2026
Jul 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Restaurant Name field to /dashboard/profile.php.
1Octopus
1Octopus Server
Jun 17, 2026
Jul 15, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link.
1Softwarepublico
1I3geo
Jun 17, 2026
Jul 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via request_token.php.
1Softwarepublico
1I3geo
Jun 17, 2026
Jul 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via access_token.php.
1Softwarepublico
1I3geo
Jun 17, 2026
Jul 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability via svg2img.php.
1Fast Food Ordering System Project
1Fast Food Ordering System
Jun 17, 2026
Jul 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Fast Food Ordering System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the component /ffos/classes/Master.php?f=save_category.
1Ibm
1Websphere Application Server
Jun 17, 2026
Jul 14, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially le...Show more
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 225605.Show less
1Ibm
2Engineering Lifecycle Optimization Publishing
Engineering Lifecycle Optimization Publishing
Jun 17, 2026
Jul 14, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM Engineering Lifecycle Optimization - Publishing 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more
IBM Engineering Lifecycle Optimization - Publishing 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213655.Show less
1Veeam
1Management Pack
Jun 17, 2026
Jul 14, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft System Center 8.0. This vulnerability could be exploited by an attacker by convincing a legitimate...Show more
A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft System Center 8.0. This vulnerability could be exploited by an attacker by convincing a legitimate user to visit a crafted URL on a Veeam Management Pack for Microsoft System Center server, allowing for the execution of arbitrary scripts.Show less
1Simple E Learning System Project
1Simple E Learning System
Jun 17, 2026
Jul 14, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A vulnerability classified as problematic was found in SourceCodester Simple e-Learning System 1.0. Affected by this vulnerability is an unknown functionality of the file /vcs/claire_blake. The manipulation of the argume...Show more
A vulnerability classified as problematic was found in SourceCodester Simple e-Learning System 1.0. Affected by this vulnerability is an unknown functionality of the file /vcs/claire_blake. The manipulation of the argument Bio with the input "><script>alert(document.cookie)</script> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Bestpractical
1Request Tracker
Jun 17, 2026
Jul 14, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.
1Ublock Origin Project
1Ublock Origin
Jun 17, 2026
Jul 13, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in uBlock Origin extension before 1.41.1 allows remote attackers to run arbitrary code via a spoofed 'MessageSender.url' to the browser renderer process.
1Prestashop
1Prestashop
Jun 17, 2026
Jul 13, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
File upload vulnerability in the Catalog feature in Prestashop 1.7.6.7 allows remote attackers to run arbitrary code via the add new file page.
1Ibm
1I
Jun 17, 2026
Jul 13, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credent...Show more
IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 230516.Show less
2Enhancesoft
Osticket
2Osticket
Osticket
Jul 10, 2026
Jul 13, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web s...Show more
A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.Show less
1Ruoyi
1Ruoyi
Jun 17, 2026
Jul 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file.