CWE-79
47,450 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,450)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0. |
1Hospital Management System Project 1Hospital Management System Jun 17, 2026 Mar 15, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 HMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php. |
Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /widgets/debug.php. |
1Jenkins 1Environment Dashboard Jun 17, 2026 Mar 15, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Jenkins Environment Dashboard Plugin 1.1.10 and earlier does not escape the Environment order and the Component order configuration values in its views, resulting in a stored cross-site scripting (XSS) vulnerability expl...Show more |
1Jenkins 1List Git Branches Parameter Jun 17, 2026 Mar 15, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Jenkins List Git Branches Parameter Plugin 0.0.9 and earlier does not escape the name of the 'List Git branches (and more)' parameter, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attacke...Show more |
Jenkins global-build-stats Plugin 1.5 and earlier does not escape multiple fields in the chart configuration on the 'Global Build Stats' page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by...Show more |
1Jenkins 1Extended Choice Parameter Jun 17, 2026 Mar 15, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the value and description of extended choice parameters of radio buttons or check boxes type, resulting in a stored cross-site scrip...Show more |
1Jenkins 1Folder Based Authorization Strategy Jun 17, 2026 Mar 15, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Jenkins Folder-based Authorization Strategy Plugin 1.3 and earlier does not escape the names of roles shown on the configuration form, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attacke...Show more |
Jenkins Dashboard View Plugin 2.18 and earlier does not perform URL validation for the Iframe Portlet's Iframe source URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to c...Show more |
Jenkins Favorite Plugin 2.4.0 and earlier does not escape the names of jobs in the favorite column, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure or Item/Crea...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31. |
Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4. |
Stored XSS via File Upload in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.4.10. |
Stored XSS viva .ofd file upload in GitHub repository star7th/showdoc prior to 2.10.4. |
Stored XSS viva .webmv file upload in GitHub repository star7th/showdoc prior to 2.10.4. |
Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12. |
Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to 2.10.4. |
Stored XSS via File Upload in GitHub repository star7th/showdoc prior to 2.10.4. |
Stored XSS via File Upload in GitHub repository star7th/showdoc prior to v.2.10.4. |
Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings and Shops' Payments Methods in GitHub repository microweber/microweber prior to 1.2.11. |