← Back
CWE-79

47,455 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,455)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Moodle
1Moodle
Jun 17, 2026
Mar 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.
1Secomea
1Gatemanager
Jun 17, 2026
Mar 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session. This issue affects: Secomea GateManager Version 9.6.621421014 and all pri...Show more
Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject javascript in browser session. This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions.Show less
1Hitachienergy
1Ellipse Enterprise Asset Management
Jun 17, 2026
Mar 11, 2022
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
An attacker could exploit this vulnerability in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 by tricking a user to click on a link containing malicious code tha...Show more
An attacker could exploit this vulnerability in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to and including 9.0.25 by tricking a user to click on a link containing malicious code that would then be run by the web browser. This can result in the compromise of confidential information, or even the takeover of the user’s session.Show less
1Microweber
1Microweber
Jun 17, 2026
Mar 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.
2Debian
Horde
2Debian Linux
Horde Mime Viewer
Jun 17, 2026
Mar 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to account takeover in Horde Groupware Webmail Edition. This occurs after XSLT rendering.
1Orchardcore
1Orchardcore
Jun 17, 2026
Mar 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.
1Freetakserver Ui Project
1Freetakserver Ui
Jun 17, 2026
Mar 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
FreeTAKServer-UI v1.9.8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Callsign parameter.
1Orchardcore
1Orchardcore
Jun 17, 2026
Mar 11, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0.
1Jeecg
1Jeecg Boot
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross Site Scripting (XSS) vulnerabilitiy exits in jeecg-boot 3.0 in /jeecg-boot/jmreport/view with a mouseover event.
1Sap
1Fiori Launchpad
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Fiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
1Luocms Project
1Luocms
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.
1Ipcomm
1Ipdio Firmware
Jun 17, 2026
Mar 10, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Persistent cross-site scripting (XSS) in the web interface of ipDIO allows an authenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into specific fields. The XSS payload will be exec...Show more
Persistent cross-site scripting (XSS) in the web interface of ipDIO allows an authenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into specific fields. The XSS payload will be executed when a legitimate user attempts to upload, copy, download, or delete an existing configuration (Administrative Services).Show less
1Sap
1Focused Run
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The SAP Focused Run (Real User Monitoring) - versions 200, 300, REST service does not sufficiently sanitize the input name of the file using multipart/form-data, resulting in Cross-Site Scripting (XSS) vulnerability.
1Sap
1Netweaver Enterprise Portal
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.This reflected cross-site scripting...Show more
SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.This reflected cross-site scripting attack can be used to non-permanently deface or modify displayed content of portal Website. The execution of the script content by a victim registered on the portal could compromise the confidentiality and integrity of victim’s web browser.Show less
1Sap
1Netweaver Enterprise Portal
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
1Exlibrisgroup
1Aleph 500
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in the component cgi-bin/ej.cgi of Ex libris ALEPH 500 v18.1 and v20 allows attackers to execute arbitrary web scripts or HTML.
1Marktext
1Marktext
Jun 17, 2026
Mar 10, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting vulnerability in marktext versions prior to v0.17.0 due to improper handling of the link (with javascript: scheme) inside the document may allow an attacker to execute an arbitrary script on...Show more
A stored cross-site scripting vulnerability in marktext versions prior to v0.17.0 due to improper handling of the link (with javascript: scheme) inside the document may allow an attacker to execute an arbitrary script on the PC of the user using marktext.Show less
1Ipcomm
1Ipdio Firmware
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Persistent cross-site scripting in the web interface of ipDIO allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into a specific parameter. The XSS payload will be exe...Show more
Persistent cross-site scripting in the web interface of ipDIO allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into a specific parameter. The XSS payload will be executed when a legitimate user attempts to review history.Show less
1Riverbed
1Steelcentral Appinternals Dynamic Sampling Agent
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
It was discovered that the /DsaDataTest endpoint is susceptible to Cross-site scripting (XSS) attack. It was noted that the Metric parameter does not have any input checks on the user input that allows an attacker to cra...Show more
It was discovered that the /DsaDataTest endpoint is susceptible to Cross-site scripting (XSS) attack. It was noted that the Metric parameter does not have any input checks on the user input that allows an attacker to craft its own malicious payload to trigger a XSS vulnerability.Show less
1Metaphorcreations
1Post Duplicator
Jun 17, 2026
Mar 10, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Duplicate Title" text box execu...Show more
A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Duplicate Title" text box executes whenever the user opens the Settings Page of the Post Duplicator Plugin or the application root page after duplicating any of the existing posts.Show less