← Back
CWE-79

47,403 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,403)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Glpi Project
1Glpi
Jun 17, 2026
Jun 9, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Kanban is a GLPI view to display Projects, Tickets, Changes or Problems on a tas...Show more
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Kanban is a GLPI view to display Projects, Tickets, Changes or Problems on a task board. In versions prior to 10.0.1 a user can exploit a cross site scripting vulnerability in Kanban by injecting HTML code in its user name. Users are advised to upgrade. There are no known workarounds for this issue.Show less
1Gogs
1Gogs
Jun 17, 2026
Jun 9, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Gogs is an open source self-hosted Git service. In versions of gogs prior to 0.12.9 `DisplayName` does not filter characters input from users, which leads to an XSS vulnerability when directly displayed in the issue list...Show more
Gogs is an open source self-hosted Git service. In versions of gogs prior to 0.12.9 `DisplayName` does not filter characters input from users, which leads to an XSS vulnerability when directly displayed in the issue list. This issue has been resolved in commit 155cae1d which sanitizes `DisplayName` prior to display to the user. All users of gogs are advised to upgrade. Users unable to upgrade should check their users' display names for malicious characters.Show less
1Rosariosis
1Rosariosis
Jun 17, 2026
Jun 9, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.1.
1Kromit
1Titra
Jun 17, 2026
Jun 9, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0.
1Kromit
1Titra
Jun 17, 2026
Jun 9, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0.
1Kromit
1Titra
Jun 17, 2026
Jun 9, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0.
1Diagrams
1Drawio
Jun 17, 2026
Jun 9, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 19.0.2.
1Wolfcms
1Wolf Cms
Jun 17, 2026
Jun 9, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WolfCMS up to 0.8.3.1. It has been rated as problematic. This issue affects some unknown processing of the file /wolfcms/?/admin/user/add of the component User...Show more
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WolfCMS up to 0.8.3.1. It has been rated as problematic. This issue affects some unknown processing of the file /wolfcms/?/admin/user/add of the component User Add. The manipulation of the argument name leads to basic cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-135125 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.Show less
1Prison Management System Project
1Prison Management System
Jun 17, 2026
Jun 9, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/?page=system_info of the compon...Show more
A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/?page=system_info of the component System Name Handler. The manipulation with the input <img src="" onerror="alert(1)"> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Facturascripts
1Facturascripts
Jun 17, 2026
Jun 9, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.1.
1Ltgplc
1Rustici Software Scorm Engine
Jun 17, 2026
Jun 9, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting (XSS) vulnerability exists in the playerConfUrl parameter in the /defaultui/player/modern.html file for SCORM Engine versions < 20.1.45.914, 21.1.x < 21.1.7.219. The issue exists because...Show more
A reflected cross-site scripting (XSS) vulnerability exists in the playerConfUrl parameter in the /defaultui/player/modern.html file for SCORM Engine versions < 20.1.45.914, 21.1.x < 21.1.7.219. The issue exists because there are no limitations on the domain or format of the url supplied by the user, allowing an attacker to craft malicious urls which can trigger a reflected XSS payload in the context of a victim's browser.Show less
1Emlog Pro Project
1Emlog Pro
Jun 17, 2026
Jun 9, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Emlog Pro v 1.0.4 cross-site scripting (XSS) in Emlog Pro background management.
1Edx
1Open Edx
Jun 17, 2026
Jun 9, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Jun 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.
1Partkeepr
1Partkeepr
Jun 17, 2026
Jun 8, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories.
1Rosariosis
1Rosariosis
Jun 17, 2026
Jun 8, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.
1Librehealth
1Librehealth Ehr
Jun 17, 2026
Jun 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS.
1Greenwallet
1Woocommerce Green Wallet Gateway
Jun 17, 2026
Jun 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WooCommerce Green Wallet Gateway WordPress plugin before 1.0.2 does not escape the error_envision query parameter before outputting it to the page, leading to a Reflected Cross-Site Scripting vulnerability.
1Ncrafts
1Formcraft
Jun 17, 2026
Jun 8, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disal...Show more
The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
12code
1Wpqa Builder
Jun 17, 2026
Jun 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WPQA Builder WordPress plugin before 5.4, used as a companion for the Discy and Himer , does not sanitise and escape a parameter on its reset password form which makes it possible to perform Reflected Cross-Site Scri...Show more
The WPQA Builder WordPress plugin before 5.4, used as a companion for the Discy and Himer , does not sanitise and escape a parameter on its reset password form which makes it possible to perform Reflected Cross-Site Scripting attacksShow less