CWE-79
47,383 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,383)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Transition Scheduler add-on 6.5.0 for Atlassian Jira is prone to stored XSS via the project name to the creation function. |
1Sync 5Oxygen Publishing Engine Oxygen Xml AuthorOxygen Xml Developer+2 moreJun 17, 2026 Jul 13, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS vulnerability in search terms proposals (in online documentation generated using Oxygen XML WebHelp...Show more |
1Libconnect Project 1Libconnect Jun 17, 2026 Jul 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The libconnect extension before 7.0.8 and 8.x before 8.1.0 for TYPO3 allows XSS. |
The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3 allows XSS. |
Mogu blog 5.2 is vulnerable to Cross Site Scripting (XSS). |
1Grid Elements Project 1Grid Elements Jun 17, 2026 Jul 12, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The gridelements (aka Grid Elements) extension through 7.6.1, 8.x through 8.7.0, 9.x through 9.7.0, and 10.x through 10.2.0 extension for TYPO3 allows XSS. |
1Ameos Tarteaucitron Project 1Ameos Tarteaucitron Jun 17, 2026 Jul 12, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The ameos_tarteaucitron (aka AMEOS - TarteAuCitron GDPR cookie banner and tracking management / French RGPD compatible) extension before 1.2.23 for TYPO3 allows XSS. |
The schema (aka Embedding schema.org vocabulary) extension before 1.13.1 and 2.x before 2.5.1 for TYPO3 allows XSS. |
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with 2.3.0 and prior to 2.3.6 and 2.4.5 is vulnerable to a cross-site scripting (XSS) bug which could allow an attacker to inject...Show more |
1Sap 1Netweaver Enterprise Portal Jun 17, 2026 Jul 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled input, allows a remote attacker to conduct a Cross-Site (XSS) scripting attack. A successful expl...Show more |
1Sap 1Netweaver Enterprise Portal Jun 17, 2026 Jul 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability,...Show more |
SAP Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This attack can be used to non-perman...Show more |
1Sap 1Netweaver Enterprise Portal Jun 17, 2026 Jul 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability. |
1Sap 1Netweaver Enterprise Portal Jun 17, 2026 Jul 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability,...Show more |
1Sap 1Netweaver Enterprise Portal Jun 17, 2026 Jul 12, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the User inputs while interact...Show more |
VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in alerts. |
VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in configurations. |
The package svelte before 3.49.0 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization and to improper escape of attributes when using objects during SSR (Server-Side Rendering). Exploiting this...Show more |
1Simple Parking Management System Project 1Simple Parking Management System Jun 17, 2026 Jul 12, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability, which was classified as problematic, was found in SourceCodester Simple Parking Management System 1.0. This affects an unknown part of the file /ci_spms/admin/category. The manipulation of the argument v...Show more |
1Simple Parking Management System Project 1Simple Parking Management System Jun 17, 2026 Jul 12, 2022 N/A· v4 4.6 MEDIUM· v3 3.5 LOW· v2 A vulnerability, which was classified as problematic, has been found in SourceCodester Simple Parking Management System 1.0. Affected by this issue is some unknown functionality of the file /ci_spms/admin/search/searchin...Show more |