CWE-79
47,417 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Nimbus skin for MediaWiki through 1.37.2 (before 6f9c8fb868345701d9544a54d9752515aace39df) allows XSS in Advertise link messages. |
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS). |
Limbas 4.3.36.1319 is vulnerable to Cross Site Scripting (XSS). |
Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress via &title parameter. |
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and JavaScript code is constructed to perform an action. |
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in Mati Skiba @ Rav Messer's Ravpage plugin <= 2.16 at WordPress. |
1Footer Text Project 1Footer Text Jun 17, 2026 Apr 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin <= 2.0.3 on WordPress. |
1Ibm 1Infosphere Information Server Jun 17, 2026 Apr 28, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more |
1Ibm 1Infosphere Information Server Jun 17, 2026 Apr 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more |
1Ibm 1Infosphere Information Server Jun 17, 2026 Apr 28, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more |
Stored XSS via upload plugin functionality in zip format in GitHub repository neorazorx/facturascripts prior to 2022.06. Cross-site scripting attacks can have devastating consequences. Code injected into a vulnerable app...Show more |
1Ibm 1Infosphere Information Server Jun 17, 2026 Apr 28, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more |
Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page. |
1Php Mysql Admin Panel Generator Project 1Php Mysql Admin Panel Generator Jul 9, 2026 Apr 28, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php. |
Turtlapp Turtle Note v0.7.2.6 does not filter the <meta> tag during markdown parsing, allowing attackers to execute HTML injection. |
Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions...Show more |
1Ericom 1Powerterm Webconnect Jun 17, 2026 Apr 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Ericom PowerTerm WebConnect 6.0 login portal can unsafely write an XSS payload from the AppPortal cookie into the page. |
In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible |
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible |
In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible. |