← Back
CWE-79

47,414 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,414)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Identityserver4.admin Project
1Identityserver4.admin
Jun 17, 2026
May 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in Skoruba IdentityServer4.Admin before 2.0.0 via unencoded value passed to the data-secret-value parameter.
1Zte
1Zxcdn Firmware
Jun 17, 2026
May 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing request url, and when a user clicks the url, an XSS attack will be triggered.
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
May 11, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti...Show more
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 218367.Show less
1Ibm
1Jazz Foundation
Jun 17, 2026
May 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the i...Show more
IBM Jazz Foundation (IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214619.Show less
1Sap
1Netweaver Application Server Abap
Jun 17, 2026
May 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack.
1Sap
3Netweaver As Abap Kernel
Netweaver As Abap Krnl64ucWebdispatcher
Jun 17, 2026
May 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
1Gitlab
1Gitlab
Jun 17, 2026
May 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Mark...Show more
An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. Missing invalidation of Markdown caching causes potential payloads from a previously exploitable XSS vulnerability (CVE-2022-1175) to persist and execute.Show less
1Fortinet
2Fortios
Fortiproxy
Jun 17, 2026
May 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0...Show more
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter override form may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests.Show less
1Home Owners Collection Management System Project
1Home Owners Collection Management System
Jul 9, 2026
May 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter.
1Home Owners Collection Management System Project
1Home Owners Collection Management System
Jul 9, 2026
May 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter.
1Altn
1Mdaemon
Jun 17, 2026
May 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 .
1Altn
1Mdaemon
Jun 17, 2026
May 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 .
1Surveysparrow
1Enterprise Survey Software
Jun 17, 2026
May 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Survey Sparrow Enterprise Survey Software 2022 has a Reflected cross-site scripting (XSS) vulnerability in the test parameter.
1Surveysparrow
1Enterprise Survey Software
Jun 17, 2026
May 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.
1Gitlab
1Gitlab
Jun 17, 2026
May 10, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly ha...Show more
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious requests to the PyPi API endpoint allowing the attacker to cause uncontrolled resource consumption.Show less
1Synopsys
1Black Duck Hub
Jun 17, 2026
May 10, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in Black Duck Hub’s embedded MadCap Flare documentation files could allow an unauthenticated remote attacker to conduct a cross-site scripting attack. The vulnerability is due to improper validation of us...Show more
A vulnerability in Black Duck Hub’s embedded MadCap Flare documentation files could allow an unauthenticated remote attacker to conduct a cross-site scripting attack. The vulnerability is due to improper validation of user-supplied input to MadCap Flare's framework embedded within Black Duck Hub's Help Documentation to supply content. An attacker could exploit this vulnerability by convincing a user to click a link designed to pass malicious input to the interface. A successful exploit could allow the attacker to conduct cross-site scripting attacks and gain access to sensitive browser-based information.Show less
1Wp Js Project
1Wp Js
Jun 17, 2026
May 10, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WP-JS plugin for WordPress contains a script called wp-js.php with the function wp_js_admin, that accepts unvalidated user input and echoes it back to the user. This can be used for reflected Cross-Site Scripting in...Show more
The WP-JS plugin for WordPress contains a script called wp-js.php with the function wp_js_admin, that accepts unvalidated user input and echoes it back to the user. This can be used for reflected Cross-Site Scripting in versions up to, and including, 2.0.6.Show less
1Ibm
1Guardium Data Encryption
Jun 17, 2026
May 10, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pote...Show more
IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213862.Show less
1Employee Daily Task Management System Project
1Employee Daily Task Management System
Jul 9, 2026
May 9, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS in Add New Employee Form in Sourcecodester Employee Daily Task Management System 1.0 Allows Remote Attacker to Inject/Store Arbitrary Code via the Name Field.
1Phprojekt Phpsimplygest Project
1Phprojekt Phpsimplygest
Jun 17, 2026
May 9, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a project title.