CWE-79
47,422 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,422)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Forestblog Project 1Forestblog Jun 17, 2026 Apr 16, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 ForestBlog through 2022-02-16 allows admin/profile/save userAvatar XSS during addition of a user avatar. |
Chamilo LMS v1.11.13 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /blog/blog.php. |
A reflected cross-site scripting (XSS) vulnerability in Chamilo LMS v1.11.13 allows attackers to execute arbitrary web scripts or HTML via user interaction with a crafted URL. |
2Debian Ldap Account Manager2Debian Linux Ldap Account ManagerJun 17, 2026 Apr 15, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 LDAP Account Manager (LAM) is an open source web frontend for managing entries stored in an LDAP directory. The profile editor tool has an edit profile functionality, the parameters on this page are not properly sanitize...Show more |
Multiple Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabilities in KB Support (WordPress plugin) <= 1.5.5 versions. |
1Wp Maintenance Project 1Wp Maintenance Jun 17, 2026 Apr 15, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Authenticated (admin+) Stored Cross-Site Scripting (XSS) in WP Maintenance plugin <= 6.0.7 versions. |
Multiple Cross-Site Scripting (XSS) vulnerabilities in Hubzilla 7.0.3 and earlier allows remote attacker to include arbitrary web script or HTML via the rpath parameter. |
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before service pack 3 allow remote attackers to inject arbitrary web script or HTML via a form field's help t...Show more |
1Cisco 5Cgr1000 Compute Module Ic3000 Industrial Compute GatewayIos+2 moreJun 17, 2026 Apr 15, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code...Show more |
2Fedoraproject Plantuml2Fedora PlantumlJun 17, 2026 Apr 15, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets t...Show more |
Metabase is an open source business intelligence and analytics application. In affected versions Metabase ships with an internal development endpoint `/_internal` that can allow for cross site scripting (XSS) attacks, po...Show more |
1Webnus 1Modern Events Calendar Lite Jun 17, 2026 Apr 14, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Authenticated (admin+ user) Stored Cross-Site Scripting (XSS) in Modern Events Calendar Lite (WordPress plugin) <= 6.5.1 |
1Bbraun 2Datamodule Compactplus SpacecomJun 17, 2026 Apr 14, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected cross-site scripting (XSS) vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to inject arbitrary web...Show more |
A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker...Show more |
A Cross-site Scripting (XSS) vulnerability in Juniper Networks Junos OS J-Web allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions...Show more |
A reflected Cross-site Scripting (XSS) vulnerability in J-Web of Juniper Networks Junos OS allows a network-based authenticated attacker to run malicious scripts reflected off J-Web to the victim's browser in the context...Show more |
1Coins Global 1Coins Construction Cloud Jun 17, 2026 Apr 14, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An XSS issue was discovered in COINS Construction Cloud 11.12. Due to insufficient neutralization of user input in the description of a task, it is possible to store malicious JavaScript code in the task description. Thi...Show more |
1Coins Global 1Coins Construction Cloud Jun 17, 2026 Apr 14, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in COINS Construction Cloud 11.12. Due to an inappropriate use of HTML IFRAME elements, the file upload functionality is vulnerable to a persistent Cross-Site Scripting (XSS) attack. |
1Messaging Web Application Project 1Messaging Web Application Jun 17, 2026 Apr 14, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Sourcecodester Messaging Web Application 1.0 is vulnerable to stored XSS. If a sender inserts valid scripts into the chat, the script will be executed on the receiver chat. |
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious JavaScript into a failed Job Report. |