← Back
CWE-79

47,546 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,546)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pluxml
1Pluxml
Jun 17, 2026
Feb 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the author parameter.
1Boltwire
1Boltwire
Jun 17, 2026
Feb 15, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in BoltWire v7.10 and v 8.00 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the name and lastname parameters.
1Pluxml
1Pluxml
Jun 17, 2026
Feb 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content and thumbnail...Show more
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content and thumbnail parameters.Show less
1Issabel
1Pbx
Jun 17, 2026
Feb 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the username and password f...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the username and password fields.Show less
1Vicidial
1Vicidial
Jun 17, 2026
Feb 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Vicidial 2.14-783a was discovered to contain a cross-site scripting (XSS) vulnerability via the input tabs.
1Librenms
1Librenms
Jun 17, 2026
Feb 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.1.0.
1Svg Sanitizer Project
1Svg Sanitizer
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-sanitizer` library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currentl...Show more
svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-sanitizer` library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currently no workaround available.Show less
1K Link
1K Box
Jun 17, 2026
Feb 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
K-Box is a web-based application to manage documents, images, videos and geodata. Prior to version 0.33.1, a stored Cross-Site-Scripting (XSS) vulnerability is present in the markdown editor used by the document abstract...Show more
K-Box is a web-based application to manage documents, images, videos and geodata. Prior to version 0.33.1, a stored Cross-Site-Scripting (XSS) vulnerability is present in the markdown editor used by the document abstract and markdown file preview. A specifically crafted anchor link can, if clicked, execute untrusted javascript actions, like retrieving user cookies. Version 0.33.1 includes a patch that allows discarding unsafe links.Show less
1Pybbs Project
1Pybbs
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in Pybbs v6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Search box.
1Fulusso Project
1Fulusso
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Fulusso v1.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in /BindAccount/SuccessTips.js. This vulnerability allows attackers to inject malicious code into a victim user's device via ope...Show more
Fulusso v1.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in /BindAccount/SuccessTips.js. This vulnerability allows attackers to inject malicious code into a victim user's device via open redirection.Show less
1Ibm
1Cognos Analytics Mobile
Jun 17, 2026
Feb 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the inten...Show more
IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 215592.Show less
1Librenms
1Librenms
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0.
1Librenms
1Librenms
Jun 17, 2026
Feb 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.2.0.
2Fedoraproject
Phoronix Media
3Extra Packages For Enterprise Linux
FedoraPhoronix Test Suite
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2.
1Pimcore
1Pimcore
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.4 MEDIUM· v3
5.0 MEDIUM· v2
Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1.
110web
1Spidercalendar
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated...Show more
The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue.Show less
1Mappresspro
1Mappress
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting it back in the "Bad mapid" error message, leading to a Reflected Cross-Site Scripting
1Newstatpress Project
1Newstatpress
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
2Permalink Manager Lite Project
Permalink Manager Project
2Permalink Manager
Permalink Manager Lite
Jun 17, 2026
Feb 14, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a R...Show more
The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issueShow less
1Themify
1Portfolio Post
Jun 17, 2026
Feb 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to an...Show more
Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a Reflected Cross-Site ScriptingShow less