← Back
CWE-79

47,406 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Product Show Room Site Project
1Product Show Room Site
Jun 17, 2026
Jun 2, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability was found in SourceCodester Product Show Room Site 1.0. It has been declared as problematic. This vulnerability affects p=contact. The manipulation of the Message textbox with the input <script>alert(1)</...Show more
A vulnerability was found in SourceCodester Product Show Room Site 1.0. It has been declared as problematic. This vulnerability affects p=contact. The manipulation of the Message textbox with the input <script>alert(1)</script> leads to cross site scripting. The attack can be initiated remotely but requires authentication. Exploit details have been disclosed to the public.Show less
1Bbs Go Project
1Bbs Go
Jun 17, 2026
Jun 2, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
bbs-go <= 3.3.0 including Custom Edition is vulnerable to stored XSS.
1Friendsofflarum
1Upload
Jun 17, 2026
Jun 2, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
FriendsofFlarum (FoF) Upload is an extension that handles file uploads intelligently for your forum. If FoF Upload prior to version 1.2.3 is configured to allow the uploading of SVG files ('image/svg+xml'), navigating di...Show more
FriendsofFlarum (FoF) Upload is an extension that handles file uploads intelligently for your forum. If FoF Upload prior to version 1.2.3 is configured to allow the uploading of SVG files ('image/svg+xml'), navigating directly to an SVG file URI could execute arbitrary Javascript code decided by an attacker. This Javascript code could include the execution of HTTP web requests to Flarum, or any other web service. This could allow data to be leaked by an authenticated Flarum user, or, possibly, for data to be modified maliciously. This issue has been patched with v1.2.3, which now sanitizes uploaded SVG files. As a workaround, remove the ability for users to upload SVG files through FoF Upload.Show less
1School Dormitory Management System Project
1School Dormitory Management System
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:126.
1School Dormitory Management System Project
1School Dormitory Management System
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:125
1Ecommerce Project With Php And Mysqli Fruits Bazar Project
1Ecommerce Project With Php And Mysqli Fruits Bazar
Jun 17, 2026
Jun 2, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar- 1.0 is vulnerable to Cross Site Scripting (XSS) in \admin\add_cata.php via the ctg_name parameters.
1Sscms
1Siteserver Cms
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).
1Ict
2Protege Gx
Protege Wx
Jun 17, 2026
Jun 2, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.
1Deltacontrols
1Entelitouch Firmware
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to contain a cross-site scripting (XSS) vulnerability via the Username parameter. This vulnerability allows attackers to execute arbitrary web...Show more
Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to contain a cross-site scripting (XSS) vulnerability via the Username parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload.Show less
1Librenms
1Librenms
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogController.php.
1Ofcms Project
1Ofcms
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json.
1Jflyfox
1Jfinal Cms
Jun 17, 2026
Jun 2, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.
1Online Market Place Site Project
1Online Market Place Site
Jun 17, 2026
Jun 2, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in /omps/seller of Online Market Place Site v1.0 allows attackers to execute arbitrary web cripts or HTML via a crafted payload injected into the Page parameter.
1Solutions Atlantic
1Regulatory Reporting System
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to an reflected Cross-Site Scripting (XSS) vulnerability via RRSWeb/maint/ShowDocument/ShowDocument.aspx .
1Resi
1Gemini Net
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
resi-calltrace in RESI Gemini-Net 4.2 is affected by Multiple XSS issues. Unauthenticated remote attackers can inject arbitrary web script or HTML into an HTTP GET parameter that reflects user input without sanitization....Show more
resi-calltrace in RESI Gemini-Net 4.2 is affected by Multiple XSS issues. Unauthenticated remote attackers can inject arbitrary web script or HTML into an HTTP GET parameter that reflects user input without sanitization. This exists on numerous application endpoints,Show less
1Barco
1Control Room Management Suite
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checklogin.jsp endpoint. The os_username parameters is not correctly sanitized, leading to reflected XSS.
1Barco
1Control Room Management Suite
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization of the upload mechanism is leads to stored XSS.
1Barco
1Control Room Management Suite
Jun 17, 2026
Jun 2, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization in the upload mechanism is leads to reflected XSS.
1Barco
1Control Room Management Suite
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload mechanism. Lack of input sanitization in the upload mechanism leads to reflected XSS.
1Barco
1Control Room Management Suite
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bin endpoint. The URL parameters are not correctly sanitized, leading to reflected XSS.