← Back
CWE-79

47,417 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,417)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Netapp
OracleOwasp
4Active Iq Unified Manager
Enterprise Security ApiOncommand Workflow Automation+1 more
Jun 17, 2026
Apr 27, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, there is a potential for a cross-site scripting vulnerability in ESAPI caused by a inc...Show more
ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, there is a potential for a cross-site scripting vulnerability in ESAPI caused by a incorrect regular expression for "onsiteURL" in the **antisamy-esapi.xml** configuration file that can cause "javascript:" URLs to fail to be correctly sanitized. This issue is patched in ESAPI 2.3.0.0. As a workaround, manually edit the **antisamy-esapi.xml** configuration files to change the "onsiteURL" regular expression. More information about remediation of the vulnerability, including the workaround, is available in the maintainers' release notes and security bulletin.Show less
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Apr 27, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
IBM QRadar 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credent...Show more
IBM QRadar 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 220041.Show less
1Bender
2Cc612 Firmware
Icc15xx Firmware
Jun 17, 2026
Apr 27, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Bender/ebee Charge Controllers in multiple versions are prone to Cross-site Scripting. An authenticated attacker could write HTML Code into configuration values. These values are not properly escaped when displayed.
1Apifox
1Apifox
Jun 17, 2026
Apr 27, 2022
N/A· v4
9.0 CRITICAL· v3
6.0 MEDIUM· v2
Apifox through 2.1.6 is vulnerable to Cross Site Scripting (XSS) which can lead to remote code execution.
1Microweber
1Microweber
Jun 17, 2026
Apr 27, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS in /demo/module/?module=HERE in GitHub repository microweber/microweber prior to 1.2.15. Typical impact of XSS attacks.
1Get Simple
1Getsimple Cms
Jun 17, 2026
Apr 27, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the file /admin/edit.php of the Content Module. The manipulation of the argument post-content with an input...Show more
A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the file /admin/edit.php of the Content Module. The manipulation of the argument post-content with an input like <script>alert(1)</script> leads to cross site scripting. The attack may be launched remotely but requires authentication. Expoit details have been disclosed within the advisory.Show less
1Digitaldruid
1Hoteldruid
Jun 17, 2026
Apr 26, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php.
1Zcms Project
1Zcms
Jun 17, 2026
Apr 26, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
ZCMS v20170206 was discovered to contain a stored cross-site scripting (XSS) vulnerability via index.php?m=home&c=message&a=add.
1Nopcommerce
1Nopcommerce
Jun 17, 2026
Apr 26, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new post, which allows a remote attacker to execute arbitrary JavaScript code at client browser.
1Nopcommerce
1Nopcommerce
Jun 17, 2026
Apr 26, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upload an arbitrary file to the system.
1Nopcommerce
1Nopcommerce
Jun 17, 2026
Apr 26, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code to First name or Last name at Customer Info.
1Psychological Tests & Quizzes Project
1Psychological Tests & Quizzes
Jun 17, 2026
Apr 26, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19 on WordPress possible for users with contributor or higher role via &wpt_test_page_submit_button_ca...Show more
Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19 on WordPress possible for users with contributor or higher role via &wpt_test_page_submit_button_caption parameter.Show less
1Tripetto
1Tripetto
Jun 17, 2026
Apr 26, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Unauthenticated Cross-Site Scripting (XSS) vulnerability in Tripetto's Tripetto plugin <= 5.1.4 on WordPress via SVG image upload.
1Psychological Tests & Quizzes Project
1Psychological Tests & Quizzes
Jun 17, 2026
Apr 26, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19 on WordPress possible for users with contributor or higher user rights.
1Maxb
1Maxboard
Jun 17, 2026
Apr 26, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges. When uploading file in a specific menu, the verification of the files is insufficient. It allows re...Show more
Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges. When uploading file in a specific menu, the verification of the files is insufficient. It allows remote attackers to upload arbitrary files disguising them as image files.Show less
1Getgrav
1Grav
Jun 17, 2026
Apr 26, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
stored xss in GitHub repository getgrav/grav prior to 1.7.33.
1Night Mode Project
1Night Mode
Jun 17, 2026
Apr 25, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin <= 1.0.0 on WordPress via vulnerable parameters: &ntmode_page_setting[enable-me], &ntmode_page_setting[bg-color], &n...Show more
Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin <= 1.0.0 on WordPress via vulnerable parameters: &ntmode_page_setting[enable-me], &ntmode_page_setting[bg-color], &ntmode_page_setting[txt-color], &ntmode_page_setting[anc_color].Show less
1Welaunch
1Wordpress Country Selector
Jun 17, 2026
Apr 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries to access the country selector page with the specified payload as a part...Show more
Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries to access the country selector page with the specified payload as a part of the HTTP requestShow less
1Liferay
2Digital Experience Platform
Liferay Portal
Jul 9, 2026
Apr 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web scri...Show more
Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the site name.Show less
1Liferay
2Digital Experience Platform
Liferay Portal
Jul 9, 2026
Apr 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fi...Show more
Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.1.0 through 7.3.3, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19, and 7.2 before fix pack 8, allows remote attackers to inject arbitrary web script or HTML via web content template names.Show less