← Back
CWE-79

47,387 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,387)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Agent Server Parameter
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Agent Server Parameter Plugin 1.1 and earlier does not escape the name and description of Agent Server parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exp...Show more
Jenkins Agent Server Parameter Plugin 1.1 and earlier does not escape the name and description of Agent Server parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Nested View
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Jenkins Nested View Plugin 1.20 through 1.25 (both inclusive) does not escape search parameters, resulting in a reflected cross-site scripting (XSS) vulnerability.
1Jenkins
1Embeddable Build Status
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting possible values, resulting in a reflected cross-site scripting (XSS) vuln...Show more
Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting possible values, resulting in a reflected cross-site scripting (XSS) vulnerability.Show less
1Jenkins
1Junit
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
1Jenkins
1Jenkins
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by at...Show more
In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability.
1Jenkins
1Jenkins
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2...Show more
In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335) without further escaping, resulting in a cross-site scripting (XSS) vulnerability.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-19...Show more
In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.Show less
1Jflyfox
1Jfinal Cms
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.
174cms
174cmsse
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /index/notice/show.
174cms
174cmsse
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/down_resume/total/nature.
174cms
174cmsse
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/account/safety/trade.
174cms
174cmsse
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/service/increment/add/im.
174cms
174cmsse
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/view_be_browsed/total.
174cms
174cmsse
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company.
174cms
174cmsse
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /job.
174cms
174cmsse
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /index/jobfairol/show/.
1School File Management System Project
1School File Management System
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter to the Update Account form in student_profile.php.
1Flatpress
1Flatpress
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.
1School File Management System Project
1School File Management System
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Firtstname parameter to the Update Account form in student_profile.php.