← Back
CWE-79

47,383 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,383)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Litecart
1Litecart
Jun 17, 2026
Jul 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in LiteCart versions prior to 2.4.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.
1Trilium Project
1Trilium
Jun 17, 2026
Jul 10, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.53.3.
1Joomlatools
1Docman
Jun 17, 2026
Jul 10, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Site Scripting (XSS) in an image upload function
1Ibm
1Security Verify Access
Jun 17, 2026
Jul 8, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended fun...Show more
IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 221194.Show less
1Ibm
1Cics Tx
Jun 17, 2026
Jul 8, 2022
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable sy...Show more
IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 229435.Show less
1Ibm
1Cics Tx
Jun 17, 2026
Jul 8, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM CICS TX Standard and Advanced 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially l...Show more
IBM CICS TX Standard and Advanced 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229432.Show less
1Ibm
1Cics Tx
Jun 17, 2026
Jul 8, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM CICS TX Standard and Advanced 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more
IBM CICS TX Standard and Advanced 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 229430.Show less
1Ibm
1Cics Tx
Jun 17, 2026
Jul 8, 2022
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of...Show more
IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 229330.Show less
1Hpe
2Flexfabric 5945 Firmware
Flexnetwork 5130 Ei Firmware
Jun 17, 2026
Jul 8, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A potential security vulnerability has been identified in certain HPE FlexNetwork and FlexFabric switch products. The vulnerability could be remotely exploited to allow cross site scripting (XSS). HPE has made the follow...Show more
A potential security vulnerability has been identified in certain HPE FlexNetwork and FlexFabric switch products. The vulnerability could be remotely exploited to allow cross site scripting (XSS). HPE has made the following software updates to resolve the vulnerability. HPE FlexNetwork 5130EL_7.10.R3507P02 and HPE FlexFabric 5945_7.10.R6635.Show less
1Withknown
1Known
Jun 17, 2026
Jul 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG file.
1Withknown
1Known
Jun 17, 2026
Jul 8, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Your Name text field.
1Snipeitapp
1Snipe It
Jun 17, 2026
Jul 7, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
1Snipeitapp
1Snipe It
Jun 17, 2026
Jul 7, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a crafted file.
1Pi Hole
1Adminlte
Jun 17, 2026
Jul 7, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
AdminLTE is a Pi-hole Dashboard for stats and configuration. In affected versions inserting code like `<script>alert("XSS")</script>` in the field marked with "Domain to look for" and hitting <kbd>enter</kbd> (or clickin...Show more
AdminLTE is a Pi-hole Dashboard for stats and configuration. In affected versions inserting code like `<script>alert("XSS")</script>` in the field marked with "Domain to look for" and hitting <kbd>enter</kbd> (or clicking on any of the buttons) will execute the script. The user must be logged in to use this vulnerability. Usually only administrators have login access to pi-hole, minimizing the risks. Users are advised to upgrade. There are no known workarounds for this issue.Show less
1Magnolia Cms
1Magnolia Cms
Jul 9, 2026
Jul 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted SVG docu...Show more
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted SVG document, with JavaScript, for a profile picture.Show less
1Apache
1Druid
Jun 17, 2026
Jul 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks.
1Joinbookwyrm
1Bookwyrm
Jun 17, 2026
Jul 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Bookwyrm is an open source social reading and reviewing program. Versions of Bookwyrm prior to 0.4.1 did not properly sanitize html being rendered to users. Unprivileged users are able to inject scripts into user profile...Show more
Bookwyrm is an open source social reading and reviewing program. Versions of Bookwyrm prior to 0.4.1 did not properly sanitize html being rendered to users. Unprivileged users are able to inject scripts into user profiles, book descriptions, and statuses. These vulnerabilities may be exploited as cross site scripting attacks on users viewing these fields. Users are advised to upgrade to version 0.4.1. There are no known workarounds for this issue.Show less
1Humhub
1Humhub
Jun 17, 2026
Jul 7, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
HumHub is an Open Source Enterprise Social Network. Affected versions of HumHub are vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, the attacker would need a permission to administer th...Show more
HumHub is an Open Source Enterprise Social Network. Affected versions of HumHub are vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, the attacker would need a permission to administer the Spaces feature. The names of individual "spaces" are not properly escaped and so an attacker with sufficient privilege could insert malicious javascript into a space name and exploit system users who visit that space. It is recommended that the HumHub is upgraded to 1.11.4, 1.10.5. There are no known workarounds for this issue.Show less
1Eqs
1Integrity Line
Jun 17, 2026
Jul 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
EQS Integrity Line Professional through 2022-07-01 allows a stored XSS via a crafted whistleblower entry.
1Appfire
1Jira Misc Custom Fields
Jun 17, 2026
Jul 7, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Appfire Jira Misc Custom Fields (JMCF) app 2.4.6 for Atlassian Jira allows XSS via a crafted project name to the Add Auto Indexing Rule function.