CWE-79
47,394 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,394)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the MaianAffiliate admin panel. |
A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execution in the context of authenticated and unauthenticated users through the MaianAffiliate admin panel...Show more |
1Phpgurukul 1Zoo Management System Jun 17, 2026 Jun 16, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via zms/admin/public_html/save_animal?an_id=24. |
1Razormist 1Online Discussion Forum Site Jun 17, 2026 Jun 16, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Online Discussion Forum Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /odfs/classes/Master.php?f=save_category, name. |
1Online Tutor Portal Site Project 1Online Tutor Portal Site Jun 17, 2026 Jun 16, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Online Tutor Portal Site v1.0 is vulnerable to Cross Site Scripting (XSS). via /otps/classes/Master.php. |
1Online Fire Reporting System Project 1Online Fire Reporting System Jun 17, 2026 Jun 16, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Online Fire Reporting System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ofrs/classes/Master.php. |
A cross-site scripting vulnerability in the DM Section component of Haraj v3.7 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request. |
1Intechnosoftware 1User Login Log Nov 21, 2024 Jun 16, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability was found in weblizar User Login Log Plugin 2.2.1. It has been classified as problematic. Affected is an unknown function. The manipulation leads to basic cross site scripting (Stored). It is possible to...Show more |
A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate t...Show more |
1Xyzscripts 1Contact Form Manager Nov 21, 2024 Jun 16, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attac...Show more |
1Webnus 1Modern Events Calendar Lite Jun 17, 2026 Jun 16, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject an arbitrary script via unspecified vectors. |
1Johnsoncontrols 3Metasys Application And Data Server Metasys Extended Application And Data ServerMetasys Open Application ServerJun 17, 2026 Jun 15, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the MUI Graphics web in...Show more |
Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Xakuro's XO Slider plugin <= 3.3.2 at WordPress. |
Authenticated (editor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Export All URLs plugin <= 4.1 at WordPress. |
1Custom Popup Builder Project 1Custom Popup Builder Jun 17, 2026 Jun 15, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Improper Access Control vulnerability leading to multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Muneeb's Custom Popup Builder plugin <= 1.3.1 at WordPress. |
1Johnsoncontrols 3Metasys Application And Data Server Metasys Extended Application And Data ServerMetasys Open Application ServerJun 17, 2026 Jun 15, 2022 N/A· v4 5.4 MEDIUM· v3 2.1 LOW· v2 Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the web interface. |
1Subscription Manager Project 1Subscription Manager Jun 17, 2026 Jun 15, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Subscription-Manager v1.0 /main.js has a cross-site scripting (XSS) vulnerability in the machineDetail parameter. |
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark's Hotel Booking plugin <= 3.0 at WordPress. |
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11. This issue allows any user with project management permissions to inject arbitrary code into...Show more |
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in Messenger/messenger_ajax.php in REDCap 12.0.11. This issue allows any authenticated user to inject arbitrary code into the messenger title (aka new_titl...Show more |