← Back
CWE-79

47,393 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,393)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
174cms
174cmsse
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company.
174cms
174cmsse
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /job.
174cms
174cmsse
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /index/jobfairol/show/.
1School File Management System Project
1School File Management System
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter to the Update Account form in student_profile.php.
1Flatpress
1Flatpress
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.
1School File Management System Project
1School File Management System
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Firtstname parameter to the Update Account form in student_profile.php.
1Maxb
1Maxboard
Jun 17, 2026
Jun 23, 2022
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to information exposure and privilege escalation.
1Apache
1Tomcat
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposi...Show more
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.Show less
1Gwolle Guestbook Project
1Gwolle Guestbook
Nov 21, 2024
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability was found in Gwolle Guestbook Plugin 1.7.4. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to basic cross site scripting. The attack may be initiated...Show more
A vulnerability was found in Gwolle Guestbook Plugin 1.7.4. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to basic cross site scripting. The attack may be initiated remotely.Show less
1Thealpinepress
1Alpine Photo Tile For Instagram
Nov 21, 2024
Jun 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability, which was classified as problematic, has been found in Alpine PhotoTile for Instagram Plugin 1.2.7.7. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scri...Show more
A vulnerability, which was classified as problematic, has been found in Alpine PhotoTile for Instagram Plugin 1.2.7.7. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely.Show less
1Bytesforall
1Atahualpa
Nov 21, 2024
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability has been found in Atahualpa Theme and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launche...Show more
A vulnerability has been found in Atahualpa Theme and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely.Show less
1Infogami
1Infogami
Jun 17, 2026
Jun 22, 2022
N/A· v4
N/A· v3
3.5 LOW· v2
In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.
1Openlibrary
1Openlibrary
Jun 17, 2026
Jun 22, 2022
N/A· v4
N/A· v3
4.3 MEDIUM· v2
In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Reflected XSS.
1Microweber
1Microweber
Jun 17, 2026
Jun 22, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.
1Habitica
1Habitica
Jun 17, 2026
Jun 22, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.
1Frappe
1Erpnext
Jun 17, 2026
Jun 22, 2022
N/A· v4
N/A· v3
3.5 LOW· v2
ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store malicious scripts in the ‘username’ field in ‘my settings’ which can lead to full account takeover.
1Frappe
1Erpnext
Jun 17, 2026
Jun 22, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when edit...Show more
In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being validated properly. A low privileged attacker could inject arbitrary code into input fields when editing his profile.Show less
1Frappe
1Erpnext
Jun 17, 2026
Jun 22, 2022
N/A· v4
N/A· v3
3.5 LOW· v2
In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which allows a low privilege user to conduct an account takeover attack.
1Ideaco
1Idealms
Jun 17, 2026
Jun 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IdeaLMS 2022 allows reflected Cross Site Scripting (XSS) via the IdeaLMS/Class/Assessment/ PATH_INFO.
1Nukeviet
1Nukeviet
Jun 17, 2026
Jun 21, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.