CWE-79
47,421 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,421)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1. |
Store XSS in title parameter executing at EditUser Page & EditProducto page in GitHub repository neorazorx/facturascripts prior to 2022.04. Cross-site scripting attacks can have devastating consequences. Code injected in...Show more |
Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is capable of stolen the user Cookie. |
1Crypt Server Project 1Crypt Server Jun 17, 2026 Apr 22, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Crypt Server before 3.3.0 allows XSS in the index view. This is related to serial, computername, and username. |
Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Arbitrary JavaScript as the attacked user. It's the only payload I found working, you might need to pr...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Apr 22, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Apr 22, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script i...Show more |
An attacker may be able to inject client-side JavaScript code on multiple instances within all versions of Uffizio GPS Tracker. |
Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/tools. |
ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform Stored Cross-Sit...Show more |
2Antisamy Project Oracle3Antisamy Enterprise Manager Base PlatformWeblogic ServerJun 17, 2026 Apr 21, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists...Show more |
OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. |
ACS Commons version 5.1.x (and earlier) suffers from a Reflected Cross-site Scripting (XSS) vulnerability in /apps/acs-commons/content/page-compare.html endpoint via the a and b GET parameters. User input submitted via t...Show more |
1Cisco 2Unified Communications Manager Unity ConnectionJun 17, 2026 Apr 21, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthen...Show more |
A vulnerability in the authentication component of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. This vulne...Show more |
1Solarwinds 2Database Performance Analyzer Database Performance MonitorJun 17, 2026 Apr 21, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query |
Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script can be injected in tooltips using iTop customization mechanism. This provides a stored cross site scr...Show more |
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can use ticket's followups or setup login messag...Show more |
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can exploit a lack of sanitization on SVG file u...Show more |
IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to...Show more |