CWE-79
47,426 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,426)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Public Knowledge Project 1Open Journal Systems Jun 17, 2026 Apr 4, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers. |
RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS. |
1Nginxproxymanager 1Nginx Proxy Manager Jun 17, 2026 Apr 3, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion. |
Craft CMS before 3.7.29 allows XSS. |
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file). |
A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance. |
1Eaton 1Intelligent Power Protector Jun 17, 2026 Apr 1, 2022 N/A· v4 4.8 MEDIUM· v3 2.3 LOW· v2 The vulnerability exists due to insufficient validation of input from certain resources by the IPP software. The attacker would need access to the local Subnet and an administrator interaction to compromise the system. T...Show more |
1Eaton 1Intelligent Power Manager Jun 17, 2026 Apr 1, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The vulnerability exists due to insufficient validation of input of certain resources within the IPM software. This issue affects: Intelligent Power Manager (IPM 1) versions prior to 1.70. |
1Totaljs 1Content Management System Jun 17, 2026 Apr 1, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when...Show more |
1Public Knowledge Project 1Open Journal Systems Jun 17, 2026 Apr 1, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header. |
Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter. |
A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page. |
1Chikitsa 1Patient Management Software Jun 17, 2026 Mar 31, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parameter in the (1) patient/insert, (2) patient_report, (3) /appointment_report, (4) visit_report, and (5...Show more |
1Chikitsa 1Patient Management Software Jul 9, 2026 Mar 31, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parameter in (1) patient/insert, (2) patient_report, (3) appointment_report, (4) visit_report, and (5) bil...Show more |
A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pages. |
A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting.php |
1Simple Client Management System Project 1Simple Client Management System Jun 17, 2026 Mar 31, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) Add new Client and (2) Add new invoice. |
Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13. |
1Zero Channel Plus Project 1Zero Channel Plus Jun 17, 2026 Mar 31, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting vulnerability in Zero-channel BBS Plus v0.7.4 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors. |
2Netgate Pfsense2Pfsense Pfsense PlusJun 17, 2026 Mar 31, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary scr...Show more |