CWE-79
47,414 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,414)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Identityserver4.admin Project 1Identityserver4.admin Jun 17, 2026 May 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin before 2.0.0 via unencoded value passed to the data-secret-value parameter. |
ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered. |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 May 11, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti...Show more |
IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the i...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 May 11, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack. |
1Sap 3Netweaver As Abap Kernel Netweaver As Abap Krnl64ucWebdispatcherJun 17, 2026 May 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. |
An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Mark...Show more |
1Fortinet 2Fortios FortiproxyJun 17, 2026 May 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0...Show more |
1Home Owners Collection Management System Project 1Home Owners Collection Management System Jul 9, 2026 May 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter. |
1Home Owners Collection Management System Project 1Home Owners Collection Management System Jul 9, 2026 May 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter. |
An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 . |
An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 . |
1Surveysparrow 1Enterprise Survey Software Jun 17, 2026 May 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Survey Sparrow Enterprise Survey Software 2022 has a Reflected cross-site scripting (XSS) vulnerability in the test parameter. |
1Surveysparrow 1Enterprise Survey Software Jun 17, 2026 May 11, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter. |
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly ha...Show more |
A vulnerability in Black Duck Hub’s embedded MadCap Flare documentation files could allow an unauthenticated remote attacker to conduct a cross-site scripting attack. The vulnerability is due to improper validation of us...Show more |
The WP-JS plugin for WordPress contains a script called wp-js.php with the function wp_js_admin, that accepts unvalidated user input and echoes it back to the user. This can be used for reflected Cross-Site Scripting in...Show more |
1Ibm 1Guardium Data Encryption Jun 17, 2026 May 10, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pote...Show more |
1Employee Daily Task Management System Project 1Employee Daily Task Management System Jul 9, 2026 May 9, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Stored XSS in Add New Employee Form in Sourcecodester Employee Daily Task Management System 1.0 Allows Remote Attacker to Inject/Store Arbitrary Code via the Name Field. |
1Phprojekt Phpsimplygest Project 1Phprojekt Phpsimplygest Jun 17, 2026 May 9, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a project title. |