← Back
CWE-79

47,551 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,551)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Iconics
Mitsubishielectric
2Mc Works64
Mobilehmi
Jun 17, 2026
Jan 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior and ICONICS MobileHMI versions 10.96.2 and prior allows a remote unauthenticated attacker to gain authenticatio...Show more
Cross-site Scripting vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior and ICONICS MobileHMI versions 10.96.2 and prior allows a remote unauthenticated attacker to gain authentication information of an MC Works64 or MobileHMI and perform any operation using the acquired authentication information, by injecting a malicious script in the URL of a monitoring screen delivered from the MC Works64 server or MobileHMI server to an application for mobile devices and leading a legitimate user to access this URL.Show less
1Spotweb Project
1Spotweb
Jun 17, 2026
Jan 21, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page.
1Fresenius Kabi
6Agilia Connect Firmware
Agilia Partner Maintenance SoftwareLink+ Agilia Firmware+3 more
Jun 17, 2026
Jan 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 is vulnerable to reflected cross-site scripting attacks. An attacker could inject JavaScript in a GET parameter of HTTP requests and perform un...Show more
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 is vulnerable to reflected cross-site scripting attacks. An attacker could inject JavaScript in a GET parameter of HTTP requests and perform unauthorized actions such as stealing internal information and performing actions in context of an authenticated user.Show less
1Multi Restaurant Table Reservation System Project
1Multi Restaurant Table Reservation System
Jun 17, 2026
Jan 20, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters.
1Afi Solutions
1Webacms
Jun 17, 2026
Jan 20, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability exists in index.html in AFI WebACMS through 2.1.0 via the the ID parameter.
1Pimcore
1Pimcore
Jun 17, 2026
Jan 20, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.9.
1Microweber
1Microweber
Jun 17, 2026
Jan 20, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.
1Zulip
1Zulip
Jun 17, 2026
Jan 20, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6.
1Microweber
1Microweber
Jun 17, 2026
Jan 20, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
1Wangl1989
1Mysiteforme
Jun 17, 2026
Jan 20, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
mysiteforme, as of 19-12-2022, is vulnerable to Cross Site Scripting (XSS) via the add blog tag function in the blog tag in the background blog management.
1Bigbluebutton
1Bigbluebutton
Jun 17, 2026
Jan 19, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.
1Oneblog Project
1Oneblog
Jun 17, 2026
Jan 19, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8. via the add function in the operation tab list in the background.
1Phpipam
1Phpipam
Jun 17, 2026
Jan 19, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating the site settings. The "Site title" setting is injected in several locations which t...Show more
PhpIPAM v1.4.4 allows an authenticated admin user to inject persistent JavaScript code inside the "Site title" parameter while updating the site settings. The "Site title" setting is injected in several locations which triggers the XSS.Show less
1Cacti
1Cacti
Jun 17, 2026
Jan 19, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a new group via "Copy" method at user_group_admin.php.
1Cacti
1Cacti
Jun 17, 2026
Jan 19, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.
2Cacti
Debian
2Cacti
Debian Linux
Jun 17, 2026
Jan 19, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.
1Tibco
3Ebx
Ebx Add OnsProduct And Service Catalog Powered By Tibco Ebx
Jun 17, 2026
Jan 19, 2022
N/A· v4
9.0 CRITICAL· v3
6.0 MEDIUM· v2
The Web server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, TIBCO EBX Add-ons, TIBCO EBX Add-ons, TIBCO EBX Add-ons, and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily ex...Show more
The Web server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, TIBCO EBX Add-ons, TIBCO EBX Add-ons, TIBCO EBX Add-ons, and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.8.124 and below, TIBCO EBX: versions 5.9.3, 5.9.4, 5.9.5, 5.9.6, 5.9.7, 5.9.8, 5.9.9, 5.9.10, 5.9.11, 5.9.12, 5.9.13, 5.9.14, and 5.9.15, TIBCO EBX: versions 6.0.0, 6.0.1, 6.0.2, and 6.0.3, TIBCO EBX Add-ons: versions 3.20.18 and below, TIBCO EBX Add-ons: versions 4.1.0, 4.2.0, 4.2.1, 4.2.2, 4.3.0, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.4.0, 4.4.1, 4.4.2, 4.4.3, 4.5.0, 4.5.1, 4.5.2, 4.5.3, 4.5.4, 4.5.5, and 4.5.6, TIBCO EBX Add-ons: versions 5.0.0, 5.0.1, 5.1.0, 5.1.1, and 5.2.0, and TIBCO Product and Service Catalog powered by TIBCO EBX: versions 1.1.0 and below.Show less
1Orchardcore
1Orchardcore
Jun 17, 2026
Jan 19, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.
1Orchardcore
1Orchardcore
Jun 17, 2026
Jan 19, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in NuGet OrchardCore.Application.Cms.Targets prior to 1.2.2.
1Naviwebs
1Navigate Cms
Jun 17, 2026
Jan 19, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A reflected cross-site scripting (XSS) vulnerability in \lib\packages\themes\themes.php of Navigate CMS v2.9.4 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.