CWE-79
47,421 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,421)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to...Show more |
Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?operation=wizard_helper` page did not properly escape the user supplied parameters, allowing for a cross...Show more |
Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't properly escape the user supplied parameters, allowing for javascript injection into rendered csv files....Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0. |
1Ni 5Flexlogger G Web Development SoftwareLabview+2 moreJun 17, 2026 Apr 21, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. Depending on the product(s) in use, remediation guidance includes: install SystemLink version 2021 R3...Show more |
1Wso2 9Api Manager Api Manager AnalyticsApi Microgateway+6 moreJun 17, 2026 Apr 21, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgatew...Show more |
1Synacor 1Zimbra Collaboration Suite Jun 17, 2026 Apr 21, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboration (aka ZCS) 9.0 allows unauthenticated attackers to execute arbitrary web script or HTML via request...Show more |
An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situation with a "weird single checkbox page." |
An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascript: URL in the URL field, and another administrator clicks on it. |
An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name. |
An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters. |
An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field. |
1Originprotocol 1Origin Website Jun 17, 2026 Apr 20, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject malicious Javascript via a POST request to `/presale/join`. User-controlled data is passed with no s...Show more |
wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code highlighting” in the wire-webapp resulted in the possibility of injecting and executing arbitrary HTML...Show more |
1Olivetti 1D Color Mf3555 Firmware Jun 17, 2026 Apr 20, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An XSS issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application doesn't properly check parameters, sent in a /dvcset/sysset/set.cgi POST request via the arg01.Hostname field, before s...Show more |
The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Users.php` |
The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQUEST['page'] parameter in`/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Comments.php` |
1Andrewrminion 1Wp Youtube Live Jun 17, 2026 Apr 19, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WordPress WP YouTube Live Plugin is vulnerable to Reflected Cross-Site Scripting via POST data found in the ~/inc/admin.php file which allows unauthenticated attackers to inject arbitrary web scripts in versions up t...Show more |
1Eaton 1Intelligent Power Protector Jun 17, 2026 Apr 19, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Eaton Intelligent Power Protector (IPP) prior to version 1.69 is vulnerable to stored Cross Site Scripting. The vulnerability exists due to insufficient validation of user input and improper encoding of the output for ce...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJul 9, 2026 Apr 19, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allows remote attackers to inject arbitrary web sc...Show more |