← Back
CWE-79

47,551 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,551)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fit2cloud
1Halo
Jun 17, 2026
Jan 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. An authenticated attacker can upload a carefully crafted SVG file that will trigger arbitrary javascr...Show more
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. An authenticated attacker can upload a carefully crafted SVG file that will trigger arbitrary javascript to run on a victim’s browser.Show less
1Fit2cloud
1Halo
Jun 17, 2026
Jan 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article title. An authenticated attacker can inject arbitrary javascript code that will execute on a victim’s server...Show more
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article title. An authenticated attacker can inject arbitrary javascript code that will execute on a victim’s server.Show less
2Fedoraproject
Zabbix
2Fedora
Zabbix
Jun 17, 2026
Jan 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for gr...Show more
An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire and the actor can steal session cookies and perform session hijacking to impersonate users or take over their accounts.Show less
1Crowcpp
1Crow
Jun 17, 2026
Jan 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
This affects the package Crow before 0.3+4. When using attributes without quotes in the template, an attacker can manipulate the input to introduce additional attributes, potentially executing code. This may lead to a Cr...Show more
This affects the package Crow before 0.3+4. When using attributes without quotes in the template, an attacker can manipulate the input to introduce additional attributes, potentially executing code. This may lead to a Cross-site Scripting (XSS) vulnerability, assuming an attacker can influence the value entered into the template. If the template is used to render user-generated content, this vulnerability may escalate to a persistent XSS vulnerability.Show less
1Daybydaycrm
1Daybyday
Jun 17, 2026
Jan 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CSTI). A low privileged attacker can input template injection payloads in the application at various lo...Show more
In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CSTI). A low privileged attacker can input template injection payloads in the application at various locations to execute JavaScript on the client browser.Show less
1Jenkins
1Publish Over Ssh
Jun 17, 2026
Jan 12, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Jenkins Publish Over SSH Plugin 1.22 and earlier does not escape the SSH server name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.
1Jenkins
1Badge
Jun 17, 2026
Jan 12, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Badge Plugin 1.9 and earlier does not escape the description and does not check for allowed protocols when creating a badge, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers...Show more
Jenkins Badge Plugin 1.9 and earlier does not escape the description and does not check for allowed protocols when creating a badge, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
2Jenkins
Oracle
2Communications Cloud Native Core Automated Test Suite
Matrix Project
Jun 17, 2026
Jan 12, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers...Show more
Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.Show less
1Mitre
1Caldera
Jun 17, 2026
Jan 12, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in CALDERA 2.8.1. It contains multiple reflected, stored, and self XSS vulnerabilities that may be exploited by authenticated and unauthenticated attackers.
1Lorensbergs
1Connect2
Jun 17, 2026
Jan 12, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Lorensbergs Connect2 3.13.7647.20190 is affected by an XSS vulnerability. Exploitation requires administrator privileges and is performed through the Wizard editor of the application. The attack requires an administrator...Show more
Lorensbergs Connect2 3.13.7647.20190 is affected by an XSS vulnerability. Exploitation requires administrator privileges and is performed through the Wizard editor of the application. The attack requires an administrator to go into the Wizard editor and enter an XSS payload within the Page title, Page Instructions, Text before, Text after, or Text on side box. Once this has been done, the administrator must click save and finally wait until any user of the application performs a booking for rental items in the booking area of the application, where the XSS triggers. NOTE: another perspective is that the administrator may require JavaScript to customize any aspect of the page rendering. There is no effective way for the product to defend users in the face of a malicious administratorShow less
1Iresturant Project
1Iresturant
Jun 17, 2026
Jan 12, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.
1Django Cms
1Django Cms
Jun 17, 2026
Jan 12, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cross Site Scripting (XSS) vulnerability. The vulnerability allows an attacker to ex...Show more
Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type, resulting in a Cross Site Scripting (XSS) vulnerability. The vulnerability allows an attacker to execute arbitrary JavaScript code in the web browser of the affected user.Show less
1Orchardcore
1Orchardcore
Jun 17, 2026
Jan 12, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
orchardcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Keystonejs
1Keystone
Jun 17, 2026
Jan 12, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
keystone is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Microsoft
1Dynamics 365
Jun 17, 2026
Jan 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
1Siemens
1Comos
Jun 17, 2026
Jan 11, 2022
N/A· v4
6.1 MEDIUM· v3
2.6 LOW· v2
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web c...Show more
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS accepts arbitrary code as attachment to tasks. This could allow an attacker to inject malicious code that is executed when loading the attachment.Show less
1Rangerstudio
1Directus
Jun 17, 2026
Jan 10, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functionality, which leads to Cross-Site Scripting vulnerability. A low privileged attacker can upload a...Show more
In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload functionality, which leads to Cross-Site Scripting vulnerability. A low privileged attacker can upload a crafted HTML file as a profile avatar, and when an admin or another user opens it, the XSS payload gets triggered.Show less
1Rangerstudio
1Directus
Jun 17, 2026
Jan 10, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG file upload in media upload functionality. A low privileged attacker can inject arbitrary javasc...Show more
In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG file upload in media upload functionality. A low privileged attacker can inject arbitrary javascript code which will be executed in a victim’s browser when they open the image URL.Show less
1Sismics
1Teedy
Jun 17, 2026
Jan 10, 2022
N/A· v4
9.0 CRITICAL· v3
3.5 LOW· v2
In Teedy, versions v1.5 through v1.9 are vulnerable to Stored Cross-Site Scripting (XSS) in the name of a created Tag. Since the Tag name is not being sanitized properly in the edit tag page, a low privileged attacker ca...Show more
In Teedy, versions v1.5 through v1.9 are vulnerable to Stored Cross-Site Scripting (XSS) in the name of a created Tag. Since the Tag name is not being sanitized properly in the edit tag page, a low privileged attacker can store malicious scripts in the name of the Tag. In the worst case, the victim who inadvertently triggers the attack is a highly privileged administrator. The injected scripts can extract the Session ID, which can lead to full Account Takeover of the administrator, and privileges escalation.Show less
1Sismics
1Teedy
Jun 17, 2026
Jan 10, 2022
N/A· v4
9.6 CRITICAL· v3
4.3 MEDIUM· v2
In Teedy, versions v1.5 through v1.9 are vulnerable to Reflected Cross-Site Scripting (XSS). The “search term" search functionality is not sufficiently sanitized while displaying the results of the search, which can be l...Show more
In Teedy, versions v1.5 through v1.9 are vulnerable to Reflected Cross-Site Scripting (XSS). The “search term" search functionality is not sufficiently sanitized while displaying the results of the search, which can be leveraged to inject arbitrary scripts. These scripts are executed in a victim’s browser when they enter the crafted URL. In the worst case, the victim who inadvertently triggers the attack is a highly privileged administrator. The injected scripts can extract the Session ID, which can lead to full Account Takeover of the administrator, by an unauthenticated attacker.Show less