← Back
CWE-79

47,680 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,680)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Jan 2, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter.
1Dmproadmap Project
1Dmproadmap
Jun 17, 2026
Jan 1, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DMP Roadmap before 3.0.4 allows XSS.
1Ibm
1I
Jun 17, 2026
Dec 30, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials...Show more
IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 208404.Show less
1Jquery.terminal Project
1Jquery.terminal
Jun 17, 2026
Dec 30, 2021
N/A· v4
5.4 MEDIUM· v3
2.1 LOW· v2
jQuery Terminal Emulator is a plugin for creating command line interpreters in your applications. Versions prior to 2.31.1 contain a low impact and limited cross-site scripting (XSS) vulnerability. The code for XSS paylo...Show more
jQuery Terminal Emulator is a plugin for creating command line interpreters in your applications. Versions prior to 2.31.1 contain a low impact and limited cross-site scripting (XSS) vulnerability. The code for XSS payload is always visible, but an attacker can use other techniques to hide the code the victim sees. If the application uses the `execHash` option and executes code from URL, the attacker can use this URL to execute their code. The scope is limited because the javascript attribute used is added to span tag, so no automatic execution like with `onerror` on images is possible. This issue is fixed in version 2.31.1. As a workaround, the user can use formatting that wrap whole user input and its no op. The code for this workaround is available in the GitHub Security Advisory. The fix will only work when user of the library is not using different formatters (e.g. to highlight code in different way).Show less
1Mermaid Project
1Mermaid
Jun 17, 2026
Dec 30, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Prior to version 8.13.8, malicious diagrams can run javascrip...Show more
Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Prior to version 8.13.8, malicious diagrams can run javascript code at diagram readers' machines. Users should upgrade to version 8.13.8 to receive a patch. There are no known workarounds aside from upgrading.Show less
1Quectel
1Uc20 Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Quectel UC20 UMTS/HSPA+ UC20 6.3.14 is affected by a Cross Site Scripting (XSS) vulnerability.
1Requarks
1Wiki.js
Jun 17, 2026
Dec 29, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in th...Show more
In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in the page. That will send the JWT tokens to the attacker’s server and will lead to account takeover when accessed by the victim.Show less
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Dec 29, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Dec 29, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Qnap
1Kazoo Server
Jun 17, 2026
Dec 29, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulne...Show more
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Kazoo Server: Kazoo Server 4.11.20 and laterShow less
1If Me
1Ifme
Jun 17, 2026
Dec 29, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe.
1If Me
1Ifme
Jun 17, 2026
Dec 29, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them.
1If Me
1Ifme
Jun 17, 2026
Dec 29, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin.
1Slican
1Webcti
Jun 17, 2026
Dec 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SLICAN WebCTI 1.01 2015 is affected by a Cross Site Scripting (XSS) vulnerability. The attacker can steal the user's session by injecting malicious JavaScript codes which leads to Session Hijacking and cause user's crede...Show more
SLICAN WebCTI 1.01 2015 is affected by a Cross Site Scripting (XSS) vulnerability. The attacker can steal the user's session by injecting malicious JavaScript codes which leads to Session Hijacking and cause user's credentials theft.Show less
1Nuuo
1Nvrsolo Firmware
Jun 17, 2026
Dec 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking.
1Salesagility
1Suitecrm
Jun 17, 2026
Dec 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a dif...Show more
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268.Show less
1Safarimontage
1Safari Montage
Jun 17, 2026
Dec 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScript codes.
1Livehelperchat
1Live Helper Chat
Jun 17, 2026
Dec 28, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Openwrt
1Openwrt
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OpenWrt 21.02.1 allows XSS via the NAT Rules Name screen.
1Openwrt
1Openwrt
Jun 17, 2026
Dec 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OpenWrt 21.02.1 allows XSS via the Traffic Rules Name screen.