← Back
CWE-79

47,422 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,422)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pimcore
1Pimcore
Jun 17, 2026
Apr 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS in Tooltip in GitHub repository pimcore/pimcore prior to 10.4.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Apr 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php.
1Organizr
1Organizr
Jun 17, 2026
Apr 13, 2022
N/A· v4
8.4 HIGH· v3
6.0 MEDIUM· v2
Stored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in GitHub repository causefx/organizr prior to 2.1.1810. Account takeover and privilege escalation
1Citrix
12Sd Wan 1000 Firmware
Sd Wan 1100 FirmwareSd Wan 110 Firmware+9 more
Jun 17, 2026
Apr 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected cross site scripting (XSS)
1Citrix
1Storefront Server
Jun 17, 2026
Apr 13, 2022
N/A· v4
6.1 MEDIUM· v3
2.6 LOW· v2
Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9
1Organizr
1Organizr
Jun 17, 2026
Apr 13, 2022
N/A· v4
9.0 CRITICAL· v3
3.5 LOW· v2
Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and wor...Show more
Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.Show less
1Organizr
1Organizr
Jun 17, 2026
Apr 13, 2022
N/A· v4
9.0 CRITICAL· v3
3.5 LOW· v2
Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, se...Show more
Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.Show less
1Vanderbilt
1Redcap
Jun 17, 2026
Apr 13, 2022
N/A· v4
9.0 CRITICAL· v3
3.5 LOW· v2
A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missi...Show more
A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value. This can then be leveraged to execute a Cross-Site Request Forgery attack to escalate privileges to administrator.Show less
1Mantisbt
1Mantisbt
Jun 17, 2026
Apr 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary code (if CSP allows it) in manage_plugin_page.php and manage_plugin_uninstall.php when a crafted plu...Show more
An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary code (if CSP allows it) in manage_plugin_page.php and manage_plugin_uninstall.php when a crafted plugin is installed.Show less
1Cmsimple
1Cmsimple
Jun 17, 2026
Apr 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature.
1Froxlor
1Froxlor
Jun 17, 2026
Apr 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Froxlor through 0.10.22 does not perform validation on user input passed in the customermail GET parameter. The value of this parameter is reflected in the login webpage, allowing the injection of arbitrary HTML tags.
1Hotel Management System Project
1Hotel Management System
Jun 17, 2026
Apr 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when when /admin.php is loaded.
1Fullpage Project
1Fullpage
Jun 17, 2026
Apr 12, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
stored xss due to unsantized anchor url in GitHub repository alvarotrigo/fullpage.js prior to 4.0.4. stored xss .
1Jenkins
1Promoted Builds
Jun 17, 2026
Apr 12, 2022
N/A· v4
5.4 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not validate the names of promotions defined in Job DSL, allowing attackers with Job/Configure permission to create a promotion with an u...Show more
Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not validate the names of promotions defined in Job DSL, allowing attackers with Job/Configure permission to create a promotion with an unsafe name.Show less
2Apple
Jenkins
2Macos
Subversion
Jun 17, 2026
Apr 12, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Subversion Plugin 2.15.3 and earlier does not escape the name and description of List Subversion tags (and more) parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnera...Show more
Jenkins Subversion Plugin 2.15.3 and earlier does not escape the name and description of List Subversion tags (and more) parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Promoted Builds
Jun 17, 2026
Apr 12, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not escape the name and description of Promoted Build parameters on views displaying parameters, resulting in a stored cross-site scripti...Show more
Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not escape the name and description of Promoted Build parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Node And Label Parameter
Jun 17, 2026
Apr 12, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Node and Label parameter Plugin 1.10.3 and earlier does not escape the name and description of Node and Label parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerabil...Show more
Jenkins Node and Label parameter Plugin 1.10.3 and earlier does not escape the name and description of Node and Label parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Mask Passwords
Jun 17, 2026
Apr 12, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Mask Passwords Plugin 3.0 and earlier does not escape the name and description of Non-Stored Password parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability expl...Show more
Jenkins Mask Passwords Plugin 3.0 and earlier does not escape the name and description of Non-Stored Password parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Job Generator
Jun 17, 2026
Apr 12, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Job Generator Plugin 1.22 and earlier does not escape the name and description of Generator Parameter and Generator Choice parameters on Job Generator jobs' Build With Parameters views, resulting in a stored cros...Show more
Jenkins Job Generator Plugin 1.22 and earlier does not escape the name and description of Generator Parameter and Generator Choice parameters on Job Generator jobs' Build With Parameters views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Jira
Jun 17, 2026
Apr 12, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Jira Plugin 3.7 and earlier, except 3.6.1, does not escape the name and description of Jira Issue and Jira Release Version parameters on views displaying parameters, resulting in a stored cross-site scripting (XS...Show more
Jenkins Jira Plugin 3.7 and earlier, except 3.6.1, does not escape the name and description of Jira Issue and Jira Release Version parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less