← Back
CWE-79

47,417 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mediawiki
1Mediawiki
Jun 17, 2026
Apr 29, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Nimbus skin for MediaWiki through 1.37.2 (before 6f9c8fb868345701d9544a54d9752515aace39df) allows XSS in Advertise link messages.
1Wbce
1Wbce Cms
Jun 17, 2026
Apr 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS).
1Limbas
1Limbas
Jun 17, 2026
Apr 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Limbas 4.3.36.1319 is vulnerable to Cross Site Scripting (XSS).
1Hermit Project
1Hermit
Jun 17, 2026
Apr 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress via &title parameter.
1Mahara
1Mahara
Jun 17, 2026
Apr 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and JavaScript code is constructed to perform an action.
1Ravpage Project
1Ravpage
Jun 17, 2026
Apr 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in Mati Skiba @ Rav Messer's Ravpage plugin <= 2.16 at WordPress.
1Footer Text Project
1Footer Text
Jun 17, 2026
Apr 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin <= 2.0.3 on WordPress.
1Ibm
1Infosphere Information Server
Jun 17, 2026
Apr 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 224440.Show less
1Ibm
1Infosphere Information Server
Jun 17, 2026
Apr 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 223720.Show less
1Ibm
1Infosphere Information Server
Jun 17, 2026
Apr 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 218370.Show less
1Facturascripts
1Facturascripts
Jun 17, 2026
Apr 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS via upload plugin functionality in zip format in GitHub repository neorazorx/facturascripts prior to 2022.06. Cross-site scripting attacks can have devastating consequences. Code injected into a vulnerable app...Show more
Stored XSS via upload plugin functionality in zip format in GitHub repository neorazorx/facturascripts prior to 2022.06. Cross-site scripting attacks can have devastating consequences. Code injected into a vulnerable application can exfiltrate data or install malware on the user's machine. Attackers can masquerade as authorized users via session cookies, allowing them to perform any action allowed by the user account.Show less
1Ibm
1Infosphere Information Server
Jun 17, 2026
Apr 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 211408.Show less
1Smartptt
1Smartptt Scada
Jun 17, 2026
Apr 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page.
1Php Mysql Admin Panel Generator Project
1Php Mysql Admin Panel Generator
Jul 9, 2026
Apr 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected at /edit-db.php.
1Lyonbros
1Turtl
Jun 17, 2026
Apr 28, 2022
N/A· v4
9.0 CRITICAL· v3
6.0 MEDIUM· v2
Turtlapp Turtle Note v0.7.2.6 does not filter the <meta> tag during markdown parsing, allowing attackers to execute HTML injection.
1Shopware
1Shopware
Jun 17, 2026
Apr 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions...Show more
Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cross-site scripting in the storefront. This issue is fixed in version 5.7.9. Users of older versions may attempt to mitigate the vulnerability by using the Shopware security plugin.Show less
1Ericom
1Powerterm Webconnect
Jun 17, 2026
Apr 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Ericom PowerTerm WebConnect 6.0 login portal can unsafely write an XSS payload from the AppPortal cookie into the page.
1Jetbrains
1Intellij Idea
Jun 17, 2026
Apr 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible
1Jetbrains
1Intellij Idea
Jun 17, 2026
Apr 28, 2022
N/A· v4
3.2 LOW· v3
2.1 LOW· v2
In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
1Jetbrains
1Hub
Jun 17, 2026
Apr 28, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.