← Back
CWE-79

47,551 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,551)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qnap
1Kazoo Server
Jun 17, 2026
Dec 29, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulne...Show more
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Kazoo Server: Kazoo Server 4.11.20 and laterShow less
1If Me
1Ifme
Jun 17, 2026
Dec 29, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe.
1If Me
1Ifme
Jun 17, 2026
Dec 29, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them.
1If Me
1Ifme
Jun 17, 2026
Dec 29, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin.
1Slican
1Webcti
Jun 17, 2026
Dec 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SLICAN WebCTI 1.01 2015 is affected by a Cross Site Scripting (XSS) vulnerability. The attacker can steal the user's session by injecting malicious JavaScript codes which leads to Session Hijacking and cause user's crede...Show more
SLICAN WebCTI 1.01 2015 is affected by a Cross Site Scripting (XSS) vulnerability. The attacker can steal the user's session by injecting malicious JavaScript codes which leads to Session Hijacking and cause user's credentials theft.Show less
1Nuuo
1Nvrsolo Firmware
Jun 17, 2026
Dec 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking.
1Salesagility
1Suitecrm
Jun 17, 2026
Dec 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a dif...Show more
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268.Show less
1Safarimontage
1Safari Montage
Jun 17, 2026
Dec 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScript codes.
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Dec 28, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Openwrt
1Openwrt
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OpenWrt 21.02.1 allows XSS via the NAT Rules Name screen.
1Openwrt
1Openwrt
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OpenWrt 21.02.1 allows XSS via the Traffic Rules Name screen.
1Openwrt
1Openwrt
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OpenWrt 21.02.1 allows XSS via the Port Forwards Add Name screen.
1Netgen
1Tags Bundle
Jun 17, 2026
Dec 27, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Netgen Tags Bundle 3.4.x before 3.4.11 and 4.0.x before 4.0.15 allows XSS in the Tags Admin interface.
1Qibosoft
1Qibosoft
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add.
1Requarks
1Wiki.js
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Wiki.js is a wiki app built on Node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through non-image file uploads for file types that can be viewed directly inline in the browser. By creatin...Show more
Wiki.js is a wiki app built on Node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through non-image file uploads for file types that can be viewed directly inline in the browser. By creating a malicious file which can execute inline JS when viewed in the browser (e.g. XML files), a malicious Wiki.js user may stage a stored cross-site scripting attack. This allows the attacker to execute malicious JavaScript when the file is viewed directly by other users. The file must be opened directly by the user and will not trigger directly in a normal Wiki.js page. A patch in version 2.5.264 fixes this vulnerability by adding an optional (enabled by default) force download flag to all non-image file types, preventing the file from being viewed inline in the browser. As a workaround, disable file upload for all non-trusted users. --- Thanks to @Haxatron for reporting this vulnerability. Initially reported via https://huntr.dev/bounties/266bff09-00d9-43ca-a4bb-bb540642811f/Show less
1Requarks
1Wiki.js
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Wiki.js is a wiki app built on node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through a SVG file upload made via a custom request with a fake MIME type. By creating a crafted SVG file,...Show more
Wiki.js is a wiki app built on node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through a SVG file upload made via a custom request with a fake MIME type. By creating a crafted SVG file, a malicious Wiki.js user may stage a stored cross-site scripting attack. This allows the attacker to execute malicious JavaScript when the SVG is viewed directly by other users. Scripts do not execute when loaded inside a page via normal `<img>` tags. The malicious SVG can only be uploaded by crafting a custom request to the server with a fake MIME type. A patch in version 2.5.264 fixes this vulnerability by adding an additional file extension verification check to the optional (enabled by default) SVG sanitization step to all file uploads that match the SVG mime type. As a workaround, disable file upload for all non-trusted users.Show less
1Ibm
3Power System Ac922 (8335 Gtc) Firmware
Power System Ac922 (8335 Gtg) FirmwarePower System Ac922 (8335 Gtw) Firmware
Jun 17, 2026
Dec 27, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM OPENBMC OP910 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo...Show more
IBM OPENBMC OP910 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 212049.Show less
1Buttonizer
1Buttonizer
Jun 17, 2026
Dec 27, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before outputting them in attributes and page, which could allow high privilege users to perform Cross-Site Sc...Show more
The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before outputting them in attributes and page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Wprssaggregator
1Wp Rss Aggregator
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice...Show more
The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks, allowing any authenticated users, such as subscriber to call it and set a malicious payload in the addon parameter.Show less
1Wpfront
1Wpfront User Role Editor
Jun 17, 2026
Dec 27, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting