CWE-79
47,551 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,551)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Livehelperchat 1Live Helper Chat Jun 17, 2026 Jan 26, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
1F5 2Big Ip Domain Name System Big Ip Global Traffic ManagerJun 17, 2026 Jan 25, 2022 N/A· v4 8.8 HIGH· v3 4.3 MEDIUM· v2 On BIG-IP DNS & GTM version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed...Show more |
1F5 1Nginx Controller Api Management Jun 17, 2026 Jan 25, 2022 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript cod...Show more |
Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulnerability can take advantage to exploit multiple web attacks and stole sensitive information. This iss...Show more |
In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the parameters submitted by the user input form, any user with background permission can affe...Show more |
uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via "close registration information" input box. |
uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via the input box of the statistical code. |
1Forestblog Project 1Forestblog Jun 17, 2026 Jan 25, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A problem was found in ForestBlog, as of 2021-12-29, there is a XSS vulnerability that can be injected through the nickname input box. |
Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28. |
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A cross-site scripting (XSS) vulnerability was found in `API\ResponseTrait` in Codeigniter4 prior to version 4.1.8. Attackers can do XSS atta...Show more |
1Mediawiki 1Shortdescription Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 ShortDescription is a MediaWiki extension that provides local short description support. A cross-site scripting (XSS) vulnerability exists in versions prior to 2.3.4. On a wiki that has the ShortDescription enabled, XSS...Show more |
1Coins Global 1Coins Construction Cloud Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in COINS Construction Cloud 11.12. Due to improper input neutralization, it is vulnerable to reflected cross-site scripting (XSS) via malicious links (affecting the search window and activity view...Show more |
1Coins Global 1Coins Construction Cloud Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in COINS Construction Cloud 11.12. In several locations throughout the application, JavaScript code is passed as a URL parameter. Attackers can trivially alter this code to cause malicious behavio...Show more |
1Try My Recipe Project 1Try My Recipe Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross Site Scripting (XSS) in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) by oretnom23, allows attackers to gain the PHPSESID or other unspecified impacts via the fullname parameter to the login_registrat...Show more |
1Online Covid Vaccination Scheduler System Project 1Online Covid Vaccination Scheduler System Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross site scripting (XSS) vulnerability in Sourcecodester Online Covid Vaccination Scheduler System v1 by oretnom23, allows attackers to execute arbitrary code via the lid parameter to /scheduler/addSchedule.php. |
1The Electric Billing Management System Project 1The Electric Billing Management System Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross Site Scripting (XSS) in Sourcecodester The Electric Billing Management System 1.0 by oretnom23, allows attackers to execute arbitrary code via the about page. |
1Student Quarterly Grading System Project 1Student Quarterly Grading System Jun 17, 2026 Jan 24, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross Site Scripting (XSS) in Sourcecodester Student Quarterly Grading System by oretnom23, allows attackers to execute arbitrary code via the fullname and username parameters to the users page. |
1Php Crud Without Refresh/reload Using Ajax And Datatables Tutorial Project 1Php Crud Without Refresh/reload Using Ajax And Datatables Tutorial Jun 17, 2026 Jan 24, 2022 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_na...Show more |
1Roundupwp 1Registrations For The Events Calendar Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting |
1Crmperks 1Contact Form Entries Jun 17, 2026 Jan 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cros...Show more |