← Back
CWE-79

47,406 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Librehealth
1Librehealth Ehr
Jun 17, 2026
Jun 6, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS.
1Avantune
1Genialcloud Proj
Jun 17, 2026
Jun 6, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
1Seeddms
1Seeddms
Jun 17, 2026
Jun 6, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users man...Show more
SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject the payload inside the "Role management" menu and then trigger the payload by loading the "Users management" menuShow less
1Seeddms
1Seeddms
Jun 17, 2026
Jun 6, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The "Add category" functionality inside the "Global Keywords" menu in "SeedDMS" version 6.0.18 and 5.1.25, is prone to stored XSS which allows an attacker to inject malicious javascript code.
1Librehealth
1Librehealth Ehr
Jun 17, 2026
Jun 6, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS.
1Librehealth
1Librehealth Ehr
Jun 17, 2026
Jun 6, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username.
1Sap
1Business Objects Business Intelligence Platform
Jun 17, 2026
Jun 6, 2022
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Exploit is possi...Show more
BI Launchpad and CMC in SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Exploit is possible only when the bttoken in victim’s session is active.Show less
1Librehealth
1Librehealth Ehr
Jun 17, 2026
Jun 6, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS.
1Gitlab
1Gitlab
Jun 17, 2026
Jun 6, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary Jav...Show more
A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially crafted Jira IssuesShow less
1Fudforum
1Fudforum
Jun 17, 2026
Jun 6, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
FUDForum 3.1.2 is vulnerable to Cross Site Scripting (XSS) via page_title param in Page Manager in the Admin Control Panel.
1Fudforum
1Fudforum
Jun 17, 2026
Jun 6, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
FUDforum 3.1.2 is vulnerable to Stored XSS via Forum Name field in Forum Manager Feature.
1Flatcore
1Flatcore Cms
Jun 17, 2026
Jun 6, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sections.
1Xuxueli
1Xxl Job
Jun 17, 2026
Jun 3, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.
1Facturascripts
1Facturascripts
Jun 17, 2026
Jun 3, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Generic in GitHub repository neorazorx/facturascripts prior to 2022.09.
1Realnetworks
1Realplayer
Jun 17, 2026
Jun 3, 2022
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by Real Player to reference a file that contains an URL. It is possible to inject scri...Show more
In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by Real Player to reference a file that contains an URL. It is possible to inject script code to arbitrary domains. It is also possible to reference arbitrary local files.Show less
1Realnetworks
1Realplayer
Jun 17, 2026
Jun 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local HTTP error pages (displayed by Internet Explorer core). This leads to arbitrary code execution.
1Dell
1Powerstoreos
Jun 17, 2026
Jun 2, 2022
N/A· v4
5.5 MEDIUM· v3
3.5 LOW· v2
Dell PowerStore Versions before v2.1.1.0. contains a Stored Cross-Site Scripting vulnerability. A high privileged network attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or...Show more
Dell PowerStore Versions before v2.1.1.0. contains a Stored Cross-Site Scripting vulnerability. A high privileged network attacker could potentially exploit this vulnerability, leading to the storage of malicious HTML or JavaScript codes in a trusted application data store. When a victim user accesses the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery.Show less
1Neos
1Neos Cms
Jun 17, 2026
Jun 2, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in Neos CMS allow attackers with the editor role or higher to inject arbitrary script or HTML code using the editor function, the deletion of assets, or a workspace tit...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Neos CMS allow attackers with the editor role or higher to inject arbitrary script or HTML code using the editor function, the deletion of assets, or a workspace title. The vulnerabilities were found in versions 3.3.29 and 8.0.1 and could also be present in all intermediate versions.Show less
1Bigbluebutton
1Greenlight
Jun 17, 2026
Jun 2, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of the victim in the "Share room access" dialog if the victim has...Show more
BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The payload gets executed in the browser of the victim in the "Share room access" dialog if the victim has shared access to the particular room with the attacker previously.Show less
1Product Show Room Site Project
1Product Show Room Site
Jun 17, 2026
Jun 2, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability was found in SourceCodester Product Show Room Site 1.0. It has been rated as problematic. This issue affects the file /admin/?page=system_info/contact_info. The manipulation of the textbox Telephone with...Show more
A vulnerability was found in SourceCodester Product Show Room Site 1.0. It has been rated as problematic. This issue affects the file /admin/?page=system_info/contact_info. The manipulation of the textbox Telephone with the input <script>alert(1)</script> leads to cross site scripting. The attack may be initiated remotely but requires authentication. Exploit details have been disclosed to the public.Show less