← Back
CWE-79

47,680 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,680)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Personal Blog Cms Project
1Personal Blog Cms
Jun 17, 2026
Dec 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Blog CMS v1.0 contains a cross-site scripting (XSS) vulnerability in the /controller/CommentAdminController.java component.
1Metinfo
1Metinfo
Jun 17, 2026
Dec 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn.
1Mossle
1Lemon
Jun 17, 2026
Dec 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in the Editing component of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML.
1Mossle
1Lemon
Jun 17, 2026
Dec 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML.
1S Cms
1S Cms
Jul 9, 2026
Dec 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in /function/booksave.php.
1S Cms
1S Cms
Jul 9, 2026
Dec 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in the search function.
1Ajax.net Professional Project
1Ajax.net Professional
Jun 17, 2026
Dec 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package are vulnerable to JavaScript object injection which may result in cross site scripting when leverage...Show more
Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package are vulnerable to JavaScript object injection which may result in cross site scripting when leveraged by a malicious user. The affected core relates to JavaScript object creation when parsing json input. Releases before version 21.12.22.1 are affected. A workaround exists that replaces one of the core JavaScript files embedded in the library. See the GHSA-5q7q-qqw2-hjq7 for workaround details.Show less
1Deltaww
1Diaenergie
Jun 17, 2026
Dec 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DIAEnergie Version 1.7.5 and prior is vulnerable to multiple cross-site scripting vulnerabilities when arbitrary code is injected into the parameter “name” of the script “HandlerEnergyType.ashx”.
1Deltaww
1Diaenergie
Jun 17, 2026
Dec 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “name” of the script “DIAE_HandlerAlarmGroup.ashx”.
1Ciphercoin
1Contact Form 7 Database Addon
Jun 17, 2026
Dec 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.6.1).
1Deltaww
1Diaenergie
Jun 17, 2026
Dec 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”.
1Deltaww
1Diaenergie
Jun 17, 2026
Dec 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are returned by “.NET Request.QueryString”.
1Quest
1Kace Desktop Authority
Jun 17, 2026
Dec 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Quest KACE Desktop Authority before 11.2 allows XSS because it does not prevent untrusted HTML from reaching the jQuery.htmlPrefilter method of jQuery.
1Ibm
2Cloud Pak For Automation
Workflow Process Service
Jun 17, 2026
Dec 21, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cloud Pak for Automation 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to...Show more
IBM Cloud Pak for Automation 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 212357.Show less
1Ibm
3Business Automation Workflow
Business Process ManagerWorkflow Process Service
Jun 17, 2026
Dec 21, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in...Show more
IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 209512.Show less
1Wuzhicms
1Wuzhicms
Jun 17, 2026
Dec 21, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to steal the admin's cookie.
1Prestashop
1Prestashop
Nov 21, 2024
Dec 21, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field.
1Pimcore
1Pimcore
Jun 17, 2026
Dec 21, 2021
N/A· v4
9.0 CRITICAL· v3
6.0 MEDIUM· v2
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Adenion
1Blog2social
Jun 17, 2026
Dec 21, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scr...Show more
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issueShow less
1Icegram
1Icegram
Jun 17, 2026
Dec 21, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an att...Show more
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issueShow less