CWE-79
47,683 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,683)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Phpgurukul 1Bus Pass Management System Jun 17, 2026 Dec 16, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting vulnerability. |
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to stored cross site scripting attacks via the preferences footer. The p...Show more |
1Vehicle Service Management System Project 1Vehicle Service Management System Jun 17, 2026 Dec 16, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Owner fullname parameter in a Send Service Request in vehicle_service. |
janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
1Yetiforce 1Yetiforce Customer Relationship Management Jun 17, 2026 Dec 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
2Debian Gnome2Debian Linux EpiphanyJun 17, 2026 Dec 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page. |
2Debian Gnome2Debian Linux EpiphanyJun 17, 2026 Dec 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title. |
2Debian Gnome2Debian Linux EpiphanyJun 17, 2026 Dec 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js. |
2Debian Gnome2Debian Linux EpiphanyJun 17, 2026 Dec 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Vis...Show more |
Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admin/Index/addmenu.htmland then the .html file on the website that uses this editor (the file suffix is...Show more |
1Synacor 1Zimbra Collaboration Suite Jun 17, 2026 Dec 15, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated attackers to execute arbitrary web scripts or HTML via a ho...Show more |
Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the adm...Show more |
Thruk before 2.44 allows XSS for a quick command. |
Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php. The function exit will terminate the script and print the message to the user. The message will contain albumID which is...Show more |
1Yetiforce 1Yetiforce Customer Relationship Management Jun 17, 2026 Dec 15, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box. |
1Sofico 1Miles Rich Internet Application Jun 17, 2026 Dec 15, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Sofico Miles RIA 2020.2 Build 127964T is affected by Stored Cross Site Scripting (XSS). An attacker with access to a user account of the RIA IT or the Fleet role can create a crafted work order in the damage reports sect...Show more |
1Motorola 10T008 Firmware T100 FirmwareT101 Firmware+7 moreJun 17, 2026 Dec 15, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3.28.0.166; and T100,...Show more |
1Verint 1Workforce Optimization Jul 9, 2026 Dec 15, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter. |
1Genesys 1Workforce Management Jul 9, 2026 Dec 15, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion) via the Time-off parameter. |