CWE-79
47,551 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,551)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Gibbon CMS v22.0.01 was discovered to contain a cross-site scripting (XSS) vulnerability, that allows attackers to inject arbitrary script via name parameters. |
1Gadget Works Online Ordering System Project 1Gadget Works Online Ordering System Jun 17, 2026 Jan 28, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A Cross Site Scripting (XSS) vulnerabilty exists in Sourcecodester Gadget Works Online Ordering System in PHP/MySQLi 1.0 via the Category parameter in an add function in category/index.php. |
1Livehelperchat 1Live Helper Chat Jun 17, 2026 Jan 28, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cross-site scripting. Version 9.5.7 contains a patch for this issue. There are no known workarounds. |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Jan 27, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code. |
Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2. |
Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2. |
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jan 26, 2022 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_list. |
1Pfsense 2Pfsense Pfsense PlusJun 17, 2026 Jan 26, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 /usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jan 26, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_types. |
1Hospital's Patient Records Management System Project 1Hospital's Patient Records Management System Jun 17, 2026 Jan 26, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the specialization parameter in doctors.php |
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11. |
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11. |
BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field. |
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the ed...Show more |
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious co...Show more |
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.10. |
1Livehelperchat 1Live Helper Chat Jun 17, 2026 Jan 26, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |