← Back
CWE-79

47,472 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,472)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microweber
1Microweber
Jun 17, 2026
Feb 26, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.
1Weblate
1Weblate
Jun 17, 2026
Feb 25, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user name and language fields. Due to this improper neutralization it is possi...Show more
Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user name and language fields. Due to this improper neutralization it is possible to perform cross-site scripting via these fields. The issues were fixed in the 4.11 release. Users unable to upgrade are advised to add their own neutralize logic.Show less
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS.
1Jetbrains
1Hub
Jun 17, 2026
Feb 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS.
1Notimoo Project
1Notimoo
Jun 17, 2026
Feb 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in PaquitoSoftware Notimoo v1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted title or message in a notification.
1Hayageek
1Jquery Upload File
Jul 9, 2026
Feb 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in the fileNameStr parameter of jQuery-Upload-File v4.0.11 allows attackers to execute arbitrary web scripts or HTML via a crafted file with a Javascript payload in the file nam...Show more
A cross-site scripting (XSS) vulnerability in the fileNameStr parameter of jQuery-Upload-File v4.0.11 allows attackers to execute arbitrary web scripts or HTML via a crafted file with a Javascript payload in the file name.Show less
1Jetbrains
1Youtrack
Jun 17, 2026
Feb 25, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.
1Jetbrains
1Youtrack
Jun 17, 2026
Feb 25, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 25, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS.
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.
1Eyesofnetwork
1Eyesofnetwork
Jun 17, 2026
Feb 25, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An authenticated user can upload an XML file containing an XSS via the ITSM module of EyesOfNetwork 5.3.11, resulting in a stored XSS.
1Apache
1Jspwiki
Jun 17, 2026
Feb 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, which could allow the attacker to execute javascript in the victim's brows...Show more
A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.2 or later.Show less
1Apache
1Airflow
Jun 17, 2026
Feb 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. This issue affects Apache Airflow versions 2.2.3 and below.
1Qnap
1Nas Proxy Server
Jun 17, 2026
Feb 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulne...Show more
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and laterShow less
1Qnap
1Nas Proxy Server
Jun 17, 2026
Feb 25, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulne...Show more
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and laterShow less
1Hpe
1Oneview Global Dashboard
Jun 17, 2026
Feb 24, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A remote cross-site scripting vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard.
1Amazon
1Awsui/components React
Jun 17, 2026
Feb 24, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
@awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed for user interface development. Multiple components in versions before 3.0.367 have been found to n...Show more
@awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed for user interface development. Multiple components in versions before 3.0.367 have been found to not properly neutralize user input and may allow for javascript injection. Users are advised to upgrade to version 3.0.367 or later. There are no known workarounds for this issue.Show less
1Veronalabs
1Wp Statistics
Jun 17, 2026
Feb 24, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows atta...Show more
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.Show less
1Veronalabs
1Wp Statistics
Jun 17, 2026
Feb 24, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows at...Show more
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.Show less
1Veronalabs
1Wp Statistics
Jun 17, 2026
Feb 24, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers to...Show more
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.Show less