CWE-79
47,406 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,406)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Product Show Room Site Project 1Product Show Room Site Jun 17, 2026 Jun 2, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A vulnerability was found in SourceCodester Product Show Room Site 1.0. It has been declared as problematic. This vulnerability affects p=contact. The manipulation of the Message textbox with the input <script>alert(1)</...Show more |
bbs-go <= 3.3.0 including Custom Edition is vulnerable to stored XSS. |
FriendsofFlarum (FoF) Upload is an extension that handles file uploads intelligently for your forum. If FoF Upload prior to version 1.2.3 is configured to allow the uploading of SVG files ('image/svg+xml'), navigating di...Show more |
1School Dormitory Management System Project 1School Dormitory Management System Jun 17, 2026 Jun 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:126. |
1School Dormitory Management System Project 1School Dormitory Management System Jun 17, 2026 Jun 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.php:125 |
1Ecommerce Project With Php And Mysqli Fruits Bazar Project 1Ecommerce Project With Php And Mysqli Fruits Bazar Jun 17, 2026 Jun 2, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Ecommerce-project-with-php-and-mysqli-Fruits-Bazar- 1.0 is vulnerable to Cross Site Scripting (XSS) in \admin\add_cata.php via the ctg_name parameters. |
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS). |
A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter. |
1Deltacontrols 1Entelitouch Firmware Jun 17, 2026 Jun 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to contain a cross-site scripting (XSS) vulnerability via the Username parameter. This vulnerability allows attackers to execute arbitrary web...Show more |
LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogController.php. |
OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json. |
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request. |
1Online Market Place Site Project 1Online Market Place Site Jun 17, 2026 Jun 2, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site scripting (XSS) vulnerability in /omps/seller of Online Market Place Site v1.0 allows attackers to execute arbitrary web cripts or HTML via a crafted payload injected into the Page parameter. |
1Solutions Atlantic 1Regulatory Reporting System Jun 17, 2026 Jun 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to an reflected Cross-Site Scripting (XSS) vulnerability via RRSWeb/maint/ShowDocument/ShowDocument.aspx . |
resi-calltrace in RESI Gemini-Net 4.2 is affected by Multiple XSS issues. Unauthenticated remote attackers can inject arbitrary web script or HTML into an HTTP GET parameter that reflects user input without sanitization....Show more |
1Barco 1Control Room Management Suite Jun 17, 2026 Jun 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checklogin.jsp endpoint. The os_username parameters is not correctly sanitized, leading to reflected XSS. |
1Barco 1Control Room Management Suite Jun 17, 2026 Jun 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization of the upload mechanism is leads to stored XSS. |
1Barco 1Control Room Management Suite Jun 17, 2026 Jun 2, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization in the upload mechanism is leads to reflected XSS. |
1Barco 1Control Room Management Suite Jun 17, 2026 Jun 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload mechanism. Lack of input sanitization in the upload mechanism leads to reflected XSS. |
1Barco 1Control Room Management Suite Jun 17, 2026 Jun 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bin endpoint. The URL parameters are not correctly sanitized, leading to reflected XSS. |