← Back
CWE-79

47,539 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,539)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Translationexchange
1Translation Exchange
Jun 17, 2026
Feb 21, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Translation Exchange WordPress plugin through 1.0.14 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) within the Project Key text field found in the plugin's settings.
1Feedwordpress Project
1Feedwordpress
Jun 17, 2026
Feb 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.
1Sigmaplugin
1Advanced Database Cleaner
Jun 17, 2026
Feb 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
1Nasa
1Openmct
Jun 17, 2026
Feb 20, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version a...Show more
Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.Show less
1Nasa
1Openmct
Jun 17, 2026
Feb 20, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Condition Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version...Show more
Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Condition Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.Show less
1Nasa
1Openmct
Jun 17, 2026
Feb 20, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Web Page” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and pri...Show more
Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Web Page” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.Show less
1Microweber
1Microweber
Jun 17, 2026
Feb 19, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
1Wikidocs
1Wikidocs
Jun 17, 2026
Feb 19, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WikiDocs version 0.1.18 has multiple reflected XSS vulnerabilities on different pages.
1Microweber
1Microweber
Jun 17, 2026
Feb 19, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
1Sas
1Web Report Studio
Jun 17, 2026
Feb 19, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of the button placed in the...Show more
SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of the button placed in the top left. The second affects the page to which the user is directed after pressing the button, e.g., a malicious web page. In addition, the second parameter executes JavaScript, which means XSS is possible by adding a javascript: URL.Show less
1Liveconfig
1Liveconfig
Jun 17, 2026
Feb 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Stored XSS issue exists in the admin/users user administration form in LiveConfig 2.12.2.
1Broadcom
1Layer7 Api Management Oauth Toolkit
Jun 17, 2026
Feb 18, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting (XSS) vulnerability in the Symantec Layer7 API Management OAuth Toolkit (OTK) allows a remote attacker to craft a malicious URL for the OTK web UI and target OTK users with phishing attac...Show more
A reflected cross-site scripting (XSS) vulnerability in the Symantec Layer7 API Management OAuth Toolkit (OTK) allows a remote attacker to craft a malicious URL for the OTK web UI and target OTK users with phishing attacks or other social engineering techniques. A successful attack allows injecting malicious code into the OTK web UI client application.Show less
1Zerof
1Web Server
Jun 17, 2026
Feb 18, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ZEROF Web Server 2.0 allows /admin.back XSS.
1Prismjs
1Prism
Jun 17, 2026
Feb 18, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Prism is a syntax highlighting library. Starting with version 1.14.0 and prior to version 1.27.0, Prism's command line plugin can be used by attackers to achieve a cross-site scripting attack. The command line plugin did...Show more
Prism is a syntax highlighting library. Starting with version 1.14.0 and prior to version 1.27.0, Prism's command line plugin can be used by attackers to achieve a cross-site scripting attack. The command line plugin did not properly escape its output, leading to the input text being inserted into the DOM as HTML code. Server-side usage of Prism is not impacted. Websites that do not use the Command Line plugin are also not impacted. This bug has been fixed in v1.27.0. As a workaround, do not use the command line plugin on untrusted inputs, or sanitize all code blocks (remove all HTML code text) from all code blocks that use the command line plugin.Show less
1Erudika
1Scoold
Jun 17, 2026
Feb 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Scoold 1.47.2 is a Q&A/knowledge base platform written in Java. When writing a Q&A, the markdown editor is vulnerable to a XSS attack when using uppercase letters.
1Cerebrate Project
1Cerebrate
Jun 17, 2026
Feb 18, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component.
1Cerebrate Project
1Cerebrate
Jun 17, 2026
Feb 18, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-controlled description.
1Dlink
1Dsl 2730e Firmware
Jun 17, 2026
Feb 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance configuration.
1Php Fusion
1Phpfusion
Nov 21, 2024
Feb 17, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the status parameter in the CMS admin panel.
1Cisco
2Evolved Programmable Network Manager
Prime Infrastructure
Jun 17, 2026
Feb 17, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (...Show more
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.Show less