CWE-79
47,440 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,440)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Checkmk Tribe292Checkmk CheckmkJul 9, 2026 Mar 25, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device wit...Show more |
Joget DX 7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Datalist table. |
A stored cross-site scripting (XSS) issue was discovered in the OpenEMR Hospital Information Management System version 6.0.0. |
2Fedoraproject Kiwix2Fedora LibkiwixJun 17, 2026 Mar 25, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0. |
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter. |
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter. |
Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via the select and input parameters. |
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd parameter. |
Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the select and input parameters. |
1Presstigers 1Simple Event Planner Jun 17, 2026 Mar 25, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in Simple Event Planner WordPress plugin <= 1.5.4 allows user with author or higher user rights inject the malicious code via vulnerable parame...Show more |
1Presstigers 1Simple Event Planner Jun 17, 2026 Mar 25, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Authenticated Stored Cross-Site Scripting (XSS) in Simple Event Planner plugin <= 1.5.4 allows attackers with contributor or higher user roles to inject the malicious script by using vulnerable parameter &custom[add_seg]...Show more |
1Plugin Planet 1Simple Ajax Chat Jun 17, 2026 Mar 25, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Unauthenticated Stored Cross-Site Scripting (XSS) in Simple Ajax Chat <= 20220115 allows an attacker to store the malicious code. However, the attack requires specific conditions, making it hard to exploit. |
1Wp Downloadmanager Project 1Wp Downloadmanager Jun 17, 2026 Mar 25, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vulnerable parameters &download_path, &download_path_url, &download_page_ur...Show more |
A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. |
Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/WebHelp. |
A stored cross-site scripting (XSS) vulnerability in the Column module of ClassCMS v2.5 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Articles field. |
A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute arbitrary web scripts or HTML via a crafted image file. |
phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality. |
1Hongmen 1Parking Management System Jun 17, 2026 Mar 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Parking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via crafted payloads injected into the user name, password, and verification...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/data-hub prior to 1.2.4. |