← Back
CWE-79

47,450 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,450)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pimcore
1Pimcore
Jun 17, 2026
Mar 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Mar 15, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
HMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php.
1Thedigitalcraft
1Atomcms
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /widgets/debug.php.
1Jenkins
1Environment Dashboard
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Environment Dashboard Plugin 1.1.10 and earlier does not escape the Environment order and the Component order configuration values in its views, resulting in a stored cross-site scripting (XSS) vulnerability expl...Show more
Jenkins Environment Dashboard Plugin 1.1.10 and earlier does not escape the Environment order and the Component order configuration values in its views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.Show less
1Jenkins
1List Git Branches Parameter
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins List Git Branches Parameter Plugin 0.0.9 and earlier does not escape the name of the 'List Git branches (and more)' parameter, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attacke...Show more
Jenkins List Git Branches Parameter Plugin 0.0.9 and earlier does not escape the name of the 'List Git branches (and more)' parameter, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Global Build Stats
Jun 17, 2026
Mar 15, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Jenkins global-build-stats Plugin 1.5 and earlier does not escape multiple fields in the chart configuration on the 'Global Build Stats' page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by...Show more
Jenkins global-build-stats Plugin 1.5 and earlier does not escape multiple fields in the chart configuration on the 'Global Build Stats' page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.Show less
1Jenkins
1Extended Choice Parameter
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the value and description of extended choice parameters of radio buttons or check boxes type, resulting in a stored cross-site scrip...Show more
Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the value and description of extended choice parameters of radio buttons or check boxes type, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Folder Based Authorization Strategy
Jun 17, 2026
Mar 15, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Jenkins Folder-based Authorization Strategy Plugin 1.3 and earlier does not escape the names of roles shown on the configuration form, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attacke...Show more
Jenkins Folder-based Authorization Strategy Plugin 1.3 and earlier does not escape the names of roles shown on the configuration form, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.Show less
1Jenkins
1Dashboard View
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Dashboard View Plugin 2.18 and earlier does not perform URL validation for the Iframe Portlet's Iframe source URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to c...Show more
Jenkins Dashboard View Plugin 2.18 and earlier does not perform URL validation for the Iframe Portlet's Iframe source URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure views.Show less
1Jenkins
1Favorite
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Favorite Plugin 2.4.0 and earlier does not escape the names of jobs in the favorite column, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure or Item/Crea...Show more
Jenkins Favorite Plugin 2.4.0 and earlier does not escape the names of jobs in the favorite column, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure or Item/Create permissions.Show less
1Getgrav
1Grav
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
1Showdoc
1Showdoc
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4.
1Showdoc
1Showdoc
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS via File Upload in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.4.10.
1Showdoc
1Showdoc
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS viva .ofd file upload in GitHub repository star7th/showdoc prior to 2.10.4.
1Showdoc
1Showdoc
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS viva .webmv file upload in GitHub repository star7th/showdoc prior to 2.10.4.
1Microweber
1Microweber
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
1Showdoc
1Showdoc
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to 2.10.4.
1Showdoc
1Showdoc
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS via File Upload in GitHub repository star7th/showdoc prior to 2.10.4.
1Showdoc
1Showdoc
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS via File Upload in GitHub repository star7th/showdoc prior to v.2.10.4.
1Microweber
1Microweber
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11.