CWE-79
47,680 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,680)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Personal Blog Cms Project 1Personal Blog Cms Jun 17, 2026 Dec 22, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Blog CMS v1.0 contains a cross-site scripting (XSS) vulnerability in the /controller/CommentAdminController.java component. |
MetInfo 7.0 beta contains a stored cross-site scripting (XSS) vulnerability in the $name parameter of admin/?n=column&c=index&a=doAddColumn. |
A cross-site scripting (XSS) vulnerability in the Editing component of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML. |
A cross-site scripting (XSS) vulnerability in the potrtalItemName parameter in \web\PortalController.java of lemon V1.10.0 allows attackers to execute arbitrary web scripts or HTML. |
S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in /function/booksave.php. |
S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in the search function. |
1Ajax.net Professional Project 1Ajax.net Professional Jun 17, 2026 Dec 22, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package are vulnerable to JavaScript object injection which may result in cross site scripting when leverage...Show more |
DIAEnergie Version 1.7.5 and prior is vulnerable to multiple cross-site scripting vulnerabilities when arbitrary code is injected into the parameter “name” of the script “HandlerEnergyType.ashx”. |
DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “name” of the script “DIAE_HandlerAlarmGroup.ashx”. |
1Ciphercoin 1Contact Form 7 Database Addon Jun 17, 2026 Dec 22, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.6.1). |
DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “descr” of the script “DIAE_hierarchyHandler.ashx”. |
DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are returned by “.NET Request.QueryString”. |
1Quest 1Kace Desktop Authority Jun 17, 2026 Dec 22, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Quest KACE Desktop Authority before 11.2 allows XSS because it does not prevent untrusted HTML from reaching the jQuery.htmlPrefilter method of jQuery. |
1Ibm 2Cloud Pak For Automation Workflow Process ServiceJun 17, 2026 Dec 21, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Cloud Pak for Automation 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to...Show more |
1Ibm 3Business Automation Workflow Business Process ManagerWorkflow Process ServiceJun 17, 2026 Dec 21, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in...Show more |
A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to steal the admin's cookie. |
PrestaShop before 1.5.2 allows XSS via the "<object data='data:text/html" substring in the message field. |
pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scr...Show more |
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an att...Show more |