CWE-79
47,455 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,455)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Apasionados 1Customize Login Image Jun 17, 2026 Mar 10, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Custom logo link" executes when...Show more |
1Secomea 9Sitemanager 1129 Firmware Sitemanager 1139 FirmwareSitemanager 1149 Firmware+6 moreJun 17, 2026 Mar 10, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site Scripting (XSS) vulnerability in log view of Secomea SiteManager allows a logged in user to store javascript for later execution. This issue affects: Secomea SiteManager Version 9.6.621421014 and all prior ver...Show more |
Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12. |
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected versions it is possible to inject code via the voucher code form. This issue has been patched in vers...Show more |
3Debian FedoraprojectZabbix3Debian Linux FedoraFrontendJun 17, 2026 Mar 9, 2022 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 An authenticated user can create a link with reflected Javascript code inside it for graphs’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed...Show more |
2Fedoraproject Zabbix2Fedora FrontendJun 17, 2026 Mar 9, 2022 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed...Show more |
3Debian FedoraprojectZabbix3Debian Linux FedoraFrontendJun 17, 2026 Mar 9, 2022 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is chang...Show more |
3Debian FedoraprojectZabbix3Debian Linux FedoraFrontendJun 17, 2026 Mar 9, 2022 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modi...Show more |
1Wago 25750 8100 Firmware 750 8101/025 000 Firmware750 8101 Firmware+22 moreJun 17, 2026 Mar 9, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized attacker with user privileges may use this to gain access to confidential information on a PC that c...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository bookstackapp/bookstack prior to v22.02.3. |
1Siemens 2Polarion Alm Polarion Subversion WebclientJun 17, 2026 Mar 8, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in Polarion ALM (All versions < V21 R2 P2), Polarion WebClient for SVN (All versions). A cross-site scripting is present due to improper neutralization of data sent to the web page thr...Show more |
1Siemens 1Climatix Pol909 Firmware Jun 17, 2026 Mar 8, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The User Management page of affected devices is vulnerable to cross-site...Show more |
1Siemens 1Climatix Pol909 Firmware Jun 17, 2026 Mar 8, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The Group Management page of affected devices is vulnerable to cross-site...Show more |
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM...Show more |
The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disa...Show more |
The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability. |
The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallo...Show more |
1Cerber 1Wp Cerber Security, Anti Spam & Malware Scan Jun 17, 2026 Mar 7, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticat...Show more |
1Adtribes 1Product Feed Pro For Woocommerce Jun 17, 2026 Mar 7, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Product Feed PRO for WooCommerce WordPress plugin before 11.2.3 does not escape the rowCount parameter before outputting it back in an attribute via the woosea_categories_dropdown AJAX action (available to any authen...Show more |
1Videousermanuals 1White Label Cms Jun 17, 2026 Mar 7, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripti...Show more |