← Back
CWE-79

47,551 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,551)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Javaquarkbbs Project
1Javaquarkbbs
Jun 17, 2026
Jan 19, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
There is a Cross Site Scripting attack (XSS) vulnerability in JavaQuarkBBS <= v2. By entering specific statements into the background tag management module, the attack statement will be stored in the database, and the ne...Show more
There is a Cross Site Scripting attack (XSS) vulnerability in JavaQuarkBBS <= v2. By entering specific statements into the background tag management module, the attack statement will be stored in the database, and the next victim will be attacked when he accesses the tag module.Show less
1Onionshare
1Onionshare
Jun 17, 2026
Jan 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions The path parameter of the requested URL is not saniti...Show more
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions The path parameter of the requested URL is not sanitized before being passed to the QT frontend. This path is used in all components for displaying the server access history. This leads to a rendered HTML4 Subset (QT RichText editor) in the Onionshare frontend.Show less
1Car Rental Management System Project
1Car Rental Management System
Jun 17, 2026
Jan 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter.
1Broadcom
2Netmaster File Transfer Management
Netmaster Network Management For Tcp/ip
Jun 17, 2026
Jan 18, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
NetMaster 12.2 Network Management for TCP/IP and NetMaster File Transfer Management contain a XSS (Cross-Site Scripting) vulnerability in ReportCenter UI due to insufficient input validation that could potentially allow...Show more
NetMaster 12.2 Network Management for TCP/IP and NetMaster File Transfer Management contain a XSS (Cross-Site Scripting) vulnerability in ReportCenter UI due to insufficient input validation that could potentially allow an attacker to execute code on the affected machine.Show less
1Metagauss
1Profilegrid
Jun 17, 2026
Jan 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found i...Show more
The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-admin.php file which allows attackers with authenticated user access, such as subscribers, to inject arbitrary web scripts into their profile, in versions up to and including 1.2.7.Show less
1Metagauss
1Leadmagic
Jun 17, 2026
Jan 18, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The User Registration, Login & Landing Pages WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the loader_text parameter found in the ~/includes/templates/landing-page.php fil...Show more
The User Registration, Login & Landing Pages WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the loader_text parameter found in the ~/includes/templates/landing-page.php file which allows attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.2.7. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.Show less
1Buffercode
1Random Banner
Jun 17, 2026
Jan 18, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the category parameter found in the ~/include/models/model.php file which allowed attackers with administra...Show more
The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the category parameter found in the ~/include/models/model.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.1.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.Show less
1I Plugins
1Whmcs Bridge
Jun 17, 2026
Jan 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/bridge_cp.php file which allows attackers to inject arbitrary web scripts,...Show more
The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/bridge_cp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1. Due to missing authorization checks on the cc_whmcs_bridge_add_admin function, low-level authenticated users such as subscribers can exploit this vulnerability.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis
1Pimcore
1Pimcore
Jun 17, 2026
Jan 18, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7.
1Pimcore
1Pimcore
Jun 17, 2026
Jan 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.7.
1Ericsson
1Codechecker
Jun 17, 2026
Jan 18, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON d...Show more
In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON data of the /CodeCheckerService API.Show less
1Softvibe
1Saraban
Jun 17, 2026
Jan 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SoftVibe SARABAN for INFOMA 1.1 is vulnerable to stored cross-site scripting (XSS) that allows users to store scripts in certain fields (e.g. subject, description) of the document form.
1Apache
1Knox
Jun 17, 2026
Jan 17, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request that included a specially crafted request parameter could be used to red...Show more
When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to improper URL parsing. A request that included a specially crafted request parameter could be used to redirect the user to a page controlled by an attacker. This URL would need to be presented to the user outside the normal request flow through a XSS or phishing campaign.Show less
1Futurepress
1Epub.js
Jun 17, 2026
Jan 17, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
managers/views/iframe.js in FuturePress EPub.js before 0.3.89 allows XSS.
1Pimcore
1Pimcore
Jun 17, 2026
Jan 17, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Pimcore
1Pimcore
Jun 17, 2026
Jan 17, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Livehelperchat
1Livehelperchat
Jun 17, 2026
Jan 17, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Icecoder
1Icecoder
Jun 17, 2026
Jan 17, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Pluginops
1Landing Page
Jun 17, 2026
Jan 17, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.