← Back
CWE-79

47,551 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,551)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gibbonedu
1Gibbon
Jun 17, 2026
Jan 28, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Gibbon CMS v22.0.01 was discovered to contain a cross-site scripting (XSS) vulnerability, that allows attackers to inject arbitrary script via name parameters.
1Gadget Works Online Ordering System Project
1Gadget Works Online Ordering System
Jun 17, 2026
Jan 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting (XSS) vulnerabilty exists in Sourcecodester Gadget Works Online Ordering System in PHP/MySQLi 1.0 via the Category parameter in an add function in category/index.php.
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Jan 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
1Glpi Project
1Glpi
Jun 17, 2026
Jan 28, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cross-site scripting. Version 9.5.7 contains a patch for this issue. There are no known workarounds.
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Jan 27, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.
1Pimcore
1Pimcore
Jun 17, 2026
Jan 27, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.
1Craterapp
1Crater
Jun 17, 2026
Jan 27, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.
1Livehelperchat
1Livehelperchat
Jun 17, 2026
Jan 27, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
1Livehelperchat
1Livehelperchat
Jun 17, 2026
Jan 27, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
1Hospital's Patient Records Management System Project
1Hospital's Patient Records Management System
Jun 17, 2026
Jan 26, 2022
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_list.
1Pfsense
2Pfsense
Pfsense Plus
Jun 17, 2026
Jan 26, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
/usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS.
1Hospital's Patient Records Management System Project
1Hospital's Patient Records Management System
Jun 17, 2026
Jan 26, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_types.
1Hospital's Patient Records Management System Project
1Hospital's Patient Records Management System
Jun 17, 2026
Jan 26, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the specialization parameter in doctors.php
1Microweber
1Microweber
Jun 17, 2026
Jan 26, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
1Microweber
1Microweber
Jun 17, 2026
Jan 26, 2022
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
1Buddyboss
1Buddyboss
Jun 17, 2026
Jan 26, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field.
1Spip
1Spip
Jun 17, 2026
Jan 26, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the ed...Show more
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the function safehtml to the vulnerable fields. An editor is able to modify his personal information. If the editor has an article written and available, when a user goes to the public site and wants to read the author's information, the malicious code will be executed. The "Who are you" and "Website Name" fields are vulnerable.Show less
1Spip
1Spip
Jun 17, 2026
Jan 26, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious co...Show more
SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must browse to a malicious SVG file. The vulnerability allows an authenticated attacker to inject malicious code running on the client side into web pages visited by other users (stored XSS).Show less
1Pimcore
1Pimcore
Jun 17, 2026
Jan 26, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.10.
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Jan 26, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.