← Back
CWE-79

47,472 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,472)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Revealjs
1Reveal.js
Jun 17, 2026
Mar 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - DOM in GitHub repository hakimel/reveal.js prior to 4.3.0.
1Htmly
1Htmly
Jul 9, 2026
Mar 1, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.
1Pluxml
1Pluxml
Jul 9, 2026
Mar 1, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.
1Cipi
1Cipi
Jun 17, 2026
Mar 1, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cipi 3.1.15 allows Add Server stored XSS via the /api/servers name field.
1Max 3000
1Maxsite Cms
Jun 17, 2026
Feb 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3.
1Max 3000
1Maxsite Cms
Jun 17, 2026
Feb 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/files.
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Feb 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php.
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Feb 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpassword parameter at /admin-panel1.php.
1Hospital Management System Project
1Hospital Management System
Jun 17, 2026
Feb 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doctor parameter at /admin-panel1.php.
1Home Owners Collection Management System Project
1Home Owners Collection Management System
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Home Owners Collection Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the collected_by parameter under the List of Collections module.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter m1_fmmessage.
1Getgrav
1Grav
Jun 17, 2026
Feb 28, 2022
N/A· v4
4.6 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
1Icehrm
1Icehrm
Jun 17, 2026
Feb 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability in Ice Hrm 30.0.0.OS allows attackers to steal cookies via a crafted payload inserted into the First Name field.
1Icehrm
1Icehrm
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Ice Hrm 30.0.0.OS was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter in the Dashboard of the current user. This vulnerability allows attackers to compromise session crede...Show more
Ice Hrm 30.0.0.OS was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter in the Dashboard of the current user. This vulnerability allows attackers to compromise session credentials via user interaction with a crafted link.Show less
1Icehrm
1Icehrm
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Ice Hrm 30.0.0.OS was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the "key" and "fm" parameters in the component login.php.
1Cherwell
1Cherwell Service Management
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. XSS can occur via a payload in the SAMLResponse parameter of the HTTP request body.
1Obyte
1Obyte
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Obyte (formerly Byteball) Wallet before 3.4.1 allows XSS. A crafted chat message can lead to remote code execution.
1Car Driving School Management System Project
1Car Driving School Management System
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Car Driving School Management System v1.0 is affected by Cross Site Scripting (XSS) in the User Enrollment Form (Username Field). To exploit this Vulnerability, an admin views the registered user details.
1Westguardsolutions
1Ws Form
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view...Show more
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submissionShow less
1Westguardsolutions
1Ws Form
Jun 17, 2026
Feb 28, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capabilit...Show more
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less