CWE-79
47,680 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,680)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter. |
1Dmproadmap Project 1Dmproadmap Jun 17, 2026 Jan 1, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 DMP Roadmap before 3.0.4 allows XSS. |
IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials...Show more |
1Jquery.terminal Project 1Jquery.terminal Jun 17, 2026 Dec 30, 2021 N/A· v4 5.4 MEDIUM· v3 2.1 LOW· v2 jQuery Terminal Emulator is a plugin for creating command line interpreters in your applications. Versions prior to 2.31.1 contain a low impact and limited cross-site scripting (XSS) vulnerability. The code for XSS paylo...Show more |
Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Prior to version 8.13.8, malicious diagrams can run javascrip...Show more |
Quectel UC20 UMTS/HSPA+ UC20 6.3.14 is affected by a Cross Site Scripting (XSS) vulnerability. |
In Requarks wiki.js, versions 2.0.0-beta.147 to 2.5.255 are affected by Stored XSS vulnerability, where a low privileged (editor) user can upload a SVG file that contains malicious JavaScript while uploading assets in th...Show more |
1Livehelperchat 1Live Helper Chat Jun 17, 2026 Dec 29, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
1Livehelperchat 1Live Helper Chat Jun 17, 2026 Dec 29, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulne...Show more |
In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading XSS payloads fetched via an iframe. |
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be exploited by making a victim a Leader of a group which triggers the payload for them. |
In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can be directly triggered by sending an ally request to the admin. |
SLICAN WebCTI 1.01 2015 is affected by a Cross Site Scripting (XSS) vulnerability. The attacker can steal the user's session by injecting malicious JavaScript codes which leads to Session Hijacking and cause user's crede...Show more |
NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking. |
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a dif...Show more |
1Safarimontage 1Safari Montage Jun 17, 2026 Dec 28, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScript codes. |
1Livehelperchat 1Live Helper Chat Jun 17, 2026 Dec 28, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
OpenWrt 21.02.1 allows XSS via the NAT Rules Name screen. |
OpenWrt 21.02.1 allows XSS via the Traffic Rules Name screen. |