← Back
CWE-79

47,426 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,426)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totolink
1Ex300 V2 Firmware
Jun 17, 2026
Mar 31, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /home.asp.
1Oretnom23
1Banking System
Jul 9, 2026
Mar 30, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via parameters on user profile, system_info and accounts management.
1Qingscan Project
1Qingscan
Jun 17, 2026
Mar 30, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
QingScan 1.3.0 is affected by Cross Site Scripting (XSS) vulnerability in all search functions.
1Firmware Analysis And Comparison Tool Project
1Firmware Analysis And Comparison Tool
Jun 17, 2026
Mar 30, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Firmware Analysis and Comparison Tool v3.2. With administrator privileges, the attacker could perform stored XSS attacks by inserting JavaScript and HTML code in user creation functionality.
1Joomla
1Joomla
Jun 17, 2026
Mar 30, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media.
1Joomla
1Joomla
Jun 17, 2026
Mar 30, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in various components.
1Joomla
1Joomla
Jun 17, 2026
Mar 30, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fields.
1Zte
1Zxhn F680 Firmware
Jun 17, 2026
Mar 30, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
There is a stored XSS vulnerability in ZTE home gateway product. An attacker could modify the gateway name by inserting special characters and trigger an XSS attack when the user views the current topology of the device...Show more
There is a stored XSS vulnerability in ZTE home gateway product. An attacker could modify the gateway name by inserting special characters and trigger an XSS attack when the user views the current topology of the device through the management page.Show less
1Profelis
1Sambabox
Jun 17, 2026
Mar 30, 2022
N/A· v4
9.0 CRITICAL· v3
3.5 LOW· v2
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Group Functionality of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause execute arbitrary codes on the vul...Show more
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Group Functionality of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause execute arbitrary codes on the vulnerable server. This issue affects: Profelis IT Consultancy SambaBox 4.0 version 4.0 and prior versions on x86.Show less
1Douco
1Douphp
Jun 17, 2026
Mar 30, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DouPHP v1.6 Release 20220121 is affected by Cross Site Scripting (XSS) through /admin/login.php in the background, which will lead to JavaScript code execution.
1Open Emr
1Openemr
Jun 17, 2026
Mar 30, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2.
1Open Emr
1Openemr
Jun 17, 2026
Mar 30, 2022
N/A· v4
3.5 LOW· v3
3.5 LOW· v2
Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
1Open Emr
1Openemr
Jun 17, 2026
Mar 30, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
1Open Emr
1Openemr
Jun 17, 2026
Mar 30, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
1Mineweb
1Minewebcms
Jun 17, 2026
Mar 30, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository mineweb/minewebcms prior to next.
3Debian
FedoraprojectMediawiki
3Debian Linux
FedoraMediawiki
Jun 17, 2026
Mar 30, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Specia...Show more
An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.Show less
1Rsa
1Archer
Jun 17, 2026
Mar 30, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Archer 6.x through 6.10 (6.10.0.0) contains a reflected XSS vulnerability. A remote SAML-unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into suppl...Show more
Archer 6.x through 6.10 (6.10.0.0) contains a reflected XSS vulnerability. A remote SAML-unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and gets executed by the web browser in the context of the vulnerable web application.Show less
1Rsa
1Archer
Jun 17, 2026
Mar 30, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Archer 6.x through 6.9 SP3 (6.9.3.0) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying...Show more
Archer 6.x through 6.9 SP3 (6.9.3.0) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and gets executed by the web browser in the context of the vulnerable web application.Show less
1Hospital's Patient Records Management System Project
1Hospital's Patient Records Management System
Jul 9, 2026
Mar 30, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "special" field.
1Textpattern
1Textpattern
Jun 17, 2026
Mar 29, 2022
N/A· v4
8.3 HIGH· v3
5.1 MEDIUM· v2
textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they mus...Show more
textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before submitting a file upload request.Show less