CWE-79
47,408 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,408)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Meikyo 15Poe Boot Nino Poe8m2 Firmware Pose Se10 8a7b1 FirmwareSignage Rebooter Rpc M4hsi Firmware+12 moreJun 17, 2026 May 18, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting vulnerability in Rebooter(WATCH BOOT nino RPC-M2C [End of Sale] all firmware versions, WATCH BOOT light RPC-M5C [End of Sale] all firmware versions, WATCH BOOT L-zero RPC-M4L [End of Sale] all firmwa...Show more |
Cross-site Scripting (XSS) - Generic in GitHub repository erudika/para prior to v1.45.11. |
ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitatio...Show more |
Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0. |
Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0. |
In FiberHome VDSL2 Modem HG150-Ub_V3.0, a stored cross-site scripting (XSS) vulnerability in Parental Control --> Access Time Restriction --> Username field, a user cannot delete the rule due to the XSS. |
1Code Snippets Extended Project 1Code Snippets Extended Jun 17, 2026 May 17, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Persistent Cross-Site Scripting (XSS) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery (vulnerable parameters &title, &snippet_code). |
A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView. |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 May 17, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has relea...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 May 17, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has relea...Show more |
1Tibco 2Bpm Enterprise Bpm Enterprise Distribution For Silver FabricJun 17, 2026 May 17, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Workspace client component of TIBCO Software Inc.'s TIBCO BPM Enterprise and TIBCO BPM Enterprise Distribution for TIBCO Silver Fabric contains difficult to exploit Reflected Cross Site Scripting (XSS) vulnerabilitie...Show more |
The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace,...Show more |
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters. |
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php. |
1Jenkins 1Autocomplete Parameter Jun 17, 2026 May 17, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Jenkins Autocomplete Parameter Plugin 1.1 and earlier references Dropdown Autocomplete parameter and Auto Complete String parameter names in an unsafe manner from Javascript embedded in view definitions, resulting in a s...Show more |
Jenkins vboxwrapper Plugin 1.3 and earlier does not escape the name and description of VBox node parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by at...Show more |
Jenkins Selection tasks Plugin 1.0 and earlier does not escape the name and description of Script Selection task variable parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulner...Show more |
Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name and description of Promotion Level parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerabilit...Show more |
1Jenkins 1Multiselect Parameter Jun 17, 2026 May 17, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Jenkins Multiselect parameter Plugin 1.3 and earlier does not escape the name and description of Multiselect parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability explo...Show more |
Jenkins JDK Parameter Plugin 1.0 and earlier does not escape the name and description of JDK parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attack...Show more |