← Back
CWE-79

47,408 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,408)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Room Rent Portal Site Project
1Room Rent Portal Site
Jun 17, 2026
May 24, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Room-rent-portal-site v1.0 is vulnerable to Cross Site Scripting (XSS) via /rrps/classes/Master.php?f=save_category, vehicle_name.
1Oretnom23
1Toll Tax Management System
Jun 17, 2026
May 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Toll-tax-management-system v1.0 is vulnerable to Cross Site Scripting (XSS) via /ttms/classes/Master.php?f=save_recipient, vehicle_name.
1Chatbot App With Suggestion Project
1Chatbot App With Suggestion
Jun 17, 2026
May 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to Cross Site Scripting (XSS) via /simple_chat_bot/classes/Master.php?f=save_response.
1Water Billing System Project
1Water Billing System
Jun 17, 2026
May 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Water-billing-management-system v1.0 is affected by: Cross Site Scripting (XSS) via /wbms/classes/Users.php?f=save, firstname.
1Simple Social Networking Site Project
1Simple Social Networking Site
Jun 17, 2026
May 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Simple Social Networking Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /sns/classes/Users.php?f=save, firstname.
1Automotive Shop Management System Project
1Automotive Shop Management System
Jun 17, 2026
May 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Automotive Shop Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /asms/classes/Master.php?f=save_product, name.
1Badminton Center Management System Project
1Badminton Center Management System
Jun 17, 2026
May 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Badminton Center Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /bcms/classes/Master.php?f=save_court_rental.
1Sscms
1Siteserver Cms
Jun 17, 2026
May 24, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.
1Home Clean Services Management System Project
1Home Clean Services Management System
Jun 17, 2026
May 24, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability, which was classified as problematic, has been found in Home Clean Services Management System 1.0. This issue affects register.php?link=registerand. The manipulation with the input <script>alert(1)</scrip...Show more
A vulnerability, which was classified as problematic, has been found in Home Clean Services Management System 1.0. This issue affects register.php?link=registerand. The manipulation with the input <script>alert(1)</script> leads to cross site scripting. The attack may be initiated remotely but demands authentication. Exploit details have been disclosed to the public.Show less
1Student Information System Project
1Student Information System
Jun 17, 2026
May 24, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A vulnerability, which was classified as problematic, was found in Student Information System 1.0. Affected is admin/?page=students of the Student Roll module. The manipulation with the input <script>alert(1)</script> le...Show more
A vulnerability, which was classified as problematic, was found in Student Information System 1.0. Affected is admin/?page=students of the Student Roll module. The manipulation with the input <script>alert(1)</script> leads to authenticated cross site scripting. Exploit details have been disclosed to the public.Show less
1Zyxel
32Atp100 Firmware
Atp100w FirmwareAtp200 Firmware+29 more
Jun 17, 2026
May 24, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.3...Show more
A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.35 through 5.20, and VPN series firmware versions 4.35 through 5.20, that could allow an attacker to obtain some information stored in the user's browser, such as cookies or session tokens, via a malicious script.Show less
1Simple Food Website Project
1Simple Food Website
Jun 17, 2026
May 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Simple Food Website 1.0, a moderation can put the Cross Site Scripting Payload in any of the fields on http://127.0.0.1:1234/food/admin/all_users.php like Full Username, etc .This causes stored xss.
1Simple Blog Project
1Simple Blog
Jun 17, 2026
May 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any user opens a particular blog hosted on an attackers' site, XSS may occur.
1Rescue Dispatch Management System Project
1Rescue Dispatch Management System
Jun 17, 2026
May 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Rescue Dispatch Management System 1.0 suffers from Stored XSS, leading to admin account takeover via cookie stealing.
1Phpgurukul
1Online Birth Certificate System
Jul 9, 2026
May 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate System v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname or lname parameters.Show less
1Phpgurukul
1E Diary Management System
Jul 9, 2026
May 23, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.
1Netdatasoft
1Divvy Drive
Jun 17, 2026
May 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NetDataSoft DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from unspecified before v.4.6.2.0.
1Badminton Center Management System Project
1Badminton Center Management System
Jun 17, 2026
May 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the userlist module at /bcms/admin/?page=user/list. The manipulation of the argument username with the i...Show more
A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the userlist module at /bcms/admin/?page=user/list. The manipulation of the argument username with the input </td><img src="" onerror="alert(1)"><td>1 leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.Show less
1Phpgurukul
1Zoo Management System
Jun 17, 2026
May 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issue is /zoo/admin/public_html/view_accounts?type=zookeeper of the content module. The manipulation of...Show more
A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issue is /zoo/admin/public_html/view_accounts?type=zookeeper of the content module. The manipulation of the argument admin_name with the input <script>alert(1)</script> leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.Show less
1Collectiveaccess
1Providence
Jun 17, 2026
May 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8.