← Back
CWE-79

47,424 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,424)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webmin
1Webmin
Jun 17, 2026
Apr 11, 2022
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
1Ofcms Project
1Ofcms
Jun 17, 2026
Apr 10, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment text box.
1Newbee Mall Project
1Newbee Mall
Jun 17, 2026
Apr 10, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability at /admin/goods/update in Newbee-Mall v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the goodsName parameter.
1Inhandnetworks
1Inrouter 900 Firmware
Jun 17, 2026
Apr 10, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the web_exec parameter at /apply.cgi.
1Zbzcms
1Zbzcms
Jun 17, 2026
Apr 10, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
zbzcms v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the neirong parameter at /php/ajax.php.
1Tableexport.jquery.plugin Project
1Tableexport.jquery.plugin
Jun 17, 2026
Apr 10, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
XSS vulnerability with default `onCellHtmlData` function in GitHub repository hhurz/tableexport.jquery.plugin prior to 1.25.0. Transmitting cookies to third-party servers. Sending data from secure sessions to third-party...Show more
XSS vulnerability with default `onCellHtmlData` function in GitHub repository hhurz/tableexport.jquery.plugin prior to 1.25.0. Transmitting cookies to third-party servers. Sending data from secure sessions to third-party serversShow less
1Trudesk Project
1Trudesk
Jun 17, 2026
Apr 10, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive...Show more
Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.Show less
1School Club Application System Project
1School Club Application System
Jun 17, 2026
Apr 9, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability, which was classified as problematic, has been found in School Club Application System 1.0. This issue affects access to /scas/admin/. The manipulation of the parameter page with the input %22%3E%3Cimg%20...Show more
A vulnerability, which was classified as problematic, has been found in School Club Application System 1.0. This issue affects access to /scas/admin/. The manipulation of the parameter page with the input %22%3E%3Cimg%20src=x%20onerror=alert(1)%3E leads to a reflected cross site scripting. The attack may be initiated remotely and does not require any form of authentication. The exploit has been disclosed to the public and may be used.Show less
1Reprisesoftware
1Reprise License Manager
Jun 17, 2026
Apr 9, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/rlmswitchr_process file parameter via GET. Authentication is required.
1Reprisesoftware
1Reprise License Manager
Jun 17, 2026
Apr 9, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET. No authentication is required.
1Opservices
1Opmon
Jun 17, 2026
Apr 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the request URL.
1Onlyoffice
1Document Server
Jun 17, 2026
Apr 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers inject arbitrary HTML or JavaScript through /example/editor.
1Zzcms
1Zzcms
Jun 17, 2026
Apr 8, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in ZZCMS 2021. There is a cross-site scripting (XSS) vulnerability in ad_manage.php.
1Socialcodia
1Social Codia Sms
Jun 17, 2026
Apr 8, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Social Codia SMS v1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injecte...Show more
Social Codia SMS v1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.Show less
1Aerocms Project
1Aerocms
Jun 17, 2026
Apr 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload inj...Show more
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.Show less
1Aerocms Project
1Aerocms
Jun 17, 2026
Apr 8, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected int...Show more
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.Show less
1Ecommerce Codeigniter Bootstrap Project
1Ecommerce Codeigniter Bootstrap
Jun 17, 2026
Apr 8, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Apr 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.
1Exrick
1Xmall
Jul 9, 2026
Apr 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.
1Cisco
1Asyncos
Jun 17, 2026
Apr 6, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack a...Show more
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious data into a specific data field in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface.Show less