CWE-79
47,472 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,472)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross-site Scripting (XSS) - DOM in GitHub repository hakimel/reveal.js prior to 4.3.0. |
A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post. |
A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post. |
Cipi 3.1.15 allows Add Server stored XSS via the /api/servers name field. |
Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3. |
Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/files. |
1Hospital Management System Project 1Hospital Management System Jun 17, 2026 Feb 28, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php. |
1Hospital Management System Project 1Hospital Management System Jun 17, 2026 Feb 28, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpassword parameter at /admin-panel1.php. |
1Hospital Management System Project 1Hospital Management System Jun 17, 2026 Feb 28, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doctor parameter at /admin-panel1.php. |
1Home Owners Collection Management System Project 1Home Owners Collection Management System Jun 17, 2026 Feb 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Home Owners Collection Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the collected_by parameter under the List of Collections module. |
1Cmsmadesimple 1Cms Made Simple Jun 17, 2026 Feb 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage. |
Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31. |
A stored cross-site scripting (XSS) vulnerability in Ice Hrm 30.0.0.OS allows attackers to steal cookies via a crafted payload inserted into the First Name field. |
Ice Hrm 30.0.0.OS was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter in the Dashboard of the current user. This vulnerability allows attackers to compromise session crede...Show more |
Ice Hrm 30.0.0.OS was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the "key" and "fm" parameters in the component login.php. |
1Cherwell 1Cherwell Service Management Jun 17, 2026 Feb 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. XSS can occur via a payload in the SAMLResponse parameter of the HTTP request body. |
Obyte (formerly Byteball) Wallet before 3.4.1 allows XSS. A crafted chat message can lead to remote code execution. |
1Car Driving School Management System Project 1Car Driving School Management System Jun 17, 2026 Feb 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Car Driving School Management System v1.0 is affected by Cross Site Scripting (XSS) in the User Enrollment Form (Username Field). To exploit this Vulnerability, an admin views the registered user details. |
1Westguardsolutions 1Ws Form Jun 17, 2026 Feb 28, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view...Show more |
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capabilit...Show more |