← Back
CWE-79

47,426 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,426)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Public Knowledge Project
1Open Journal Systems
Jun 17, 2026
Apr 4, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers.
1Rsa
1Archer
Jun 17, 2026
Apr 4, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS.
1Nginxproxymanager
1Nginx Proxy Manager
Jun 17, 2026
Apr 3, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.
1Craftcms
1Craft Cms
Jun 17, 2026
Apr 3, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Craft CMS before 3.7.29 allows XSS.
1Dompdf Project
1Dompdf
Jun 17, 2026
Apr 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).
1Rocketchat
1Livechat
Jun 17, 2026
Apr 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance.
1Eaton
1Intelligent Power Protector
Jun 17, 2026
Apr 1, 2022
N/A· v4
4.8 MEDIUM· v3
2.3 LOW· v2
The vulnerability exists due to insufficient validation of input from certain resources by the IPP software. The attacker would need access to the local Subnet and an administrator interaction to compromise the system. T...Show more
The vulnerability exists due to insufficient validation of input from certain resources by the IPP software. The attacker would need access to the local Subnet and an administrator interaction to compromise the system. This issue affects: Intelligent Power Protector versions prior to 1.69.Show less
1Eaton
1Intelligent Power Manager
Jun 17, 2026
Apr 1, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The vulnerability exists due to insufficient validation of input of certain resources within the IPM software. This issue affects: Intelligent Power Manager (IPM 1) versions prior to 1.70.
1Totaljs
1Content Management System
Jun 17, 2026
Apr 1, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when...Show more
A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when creating a new page.Show less
1Public Knowledge Project
1Open Journal Systems
Jun 17, 2026
Apr 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.
1Maccms
1Maccms
Jun 17, 2026
Mar 31, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.
1Htmly
1Htmly
Jun 17, 2026
Mar 31, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page.
1Chikitsa
1Patient Management Software
Jun 17, 2026
Mar 31, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parameter in the (1) patient/insert, (2) patient_report, (3) /appointment_report, (4) visit_report, and (5...Show more
A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parameter in the (1) patient/insert, (2) patient_report, (3) /appointment_report, (4) visit_report, and (5) /bill_detail_report pages.Show less
1Chikitsa
1Patient Management Software
Jul 9, 2026
Mar 31, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parameter in (1) patient/insert, (2) patient_report, (3) appointment_report, (4) visit_report, and (5) bil...Show more
A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parameter in (1) patient/insert, (2) patient_report, (3) appointment_report, (4) visit_report, and (5) bill_detail_report pages. .Show less
1Htmly
1Htmly
Jun 17, 2026
Mar 31, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pages.
1Pixelimity
1Pixelimity
Jun 17, 2026
Mar 31, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting.php
1Simple Client Management System Project
1Simple Client Management System
Jun 17, 2026
Mar 31, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) Add new Client and (2) Add new invoice.
1B3log
1Vditor
Jun 17, 2026
Mar 31, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13.
1Zero Channel Plus Project
1Zero Channel Plus
Jun 17, 2026
Mar 31, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Zero-channel BBS Plus v0.7.4 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors.
2Netgate
Pfsense
2Pfsense
Pfsense Plus
Jun 17, 2026
Mar 31, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary scr...Show more
Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary script via a malicious URL.Show less