CWE-79
47,551 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,551)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Phoronix Media2Fedora Phoronix Test SuiteJun 17, 2026 Jan 10, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulnerability in the wdi_apply_changes admin page, allowing an attacker to perform such attack against any...Show more |
1Pluginus 1Woocommerce Currency Switcher Jun 17, 2026 Jan 10, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue |
Kentico Xperience 13.0.44 allows XSS via an XML document to the Media Libraries subsystem. |
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Special:CheckUserLog allows CheckUser XSS because of date mishandling, as demonstrated by an XSS payload in MediaWiki:Oc...Show more |
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The WikibaseMediaInfo component is vulnerable to XSS via the caption fields for a given media file. |
There is a Cross-Site Scripting(XSS) vulnerability in HUAWEI WS318n product when processing network settings. Due to insufficient validation of user input, a local authenticated attacker could exploit this vulnerability...Show more |
IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia...Show more |
A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerabi...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Jan 6, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform s...Show more |
Insta HMS before 12.4.10 is vulnerable to XSS because of improper validation of user-supplied input by multiple scripts. A remote attacker could exploit this vulnerability via a crafted URL to execute script in a victim'...Show more |
1Vehicle Service Management System Project 1Vehicle Service Management System Jun 17, 2026 Jan 6, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Settings Section in login panel. |
1Vehicle Service Management System Project 1Vehicle Service Management System Jun 17, 2026 Jan 6, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the User List Section in login panel. |
1Vehicle Service Management System Project 1Vehicle Service Management System Jun 17, 2026 Jan 6, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List Section in login panel. |
1Vehicle Service Management System Project 1Vehicle Service Management System Jun 17, 2026 Jan 6, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Category List Section in login panel. |
1Vehicle Service Management System Project 1Vehicle Service Management System Jun 17, 2026 Jan 6, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service Requests Section in login panel. |
1Vehicle Service Management System Project 1Vehicle Service Management System Jun 17, 2026 Jan 6, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Mechanic List Section in login panel. |
1Vehicle Service Management System Project 1Vehicle Service Management System Jun 17, 2026 Jan 6, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the My Account Section in login panel. |
A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel. |
A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel. |