← Back
CWE-79

47,683 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,683)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phpgurukul
1Bus Pass Management System
Jun 17, 2026
Dec 16, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting vulnerability.
1Galette
1Galette
Jun 17, 2026
Dec 16, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to stored cross site scripting attacks via the preferences footer. The p...Show more
Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to stored cross site scripting attacks via the preferences footer. The preference footer can only be altered by a site admin. This issue has been resolved in the 0.9.6 release and all users are advised to upgrade. There are no known workarounds.Show less
1Vehicle Service Management System Project
1Vehicle Service Management System
Jun 17, 2026
Dec 16, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Owner fullname parameter in a Send Service Request in vehicle_service.
1Meetecho
1Janus
Jun 17, 2026
Dec 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Yetiforce
1Yetiforce Customer Relationship Management
Jun 17, 2026
Dec 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
2Debian
Gnome
2Debian Linux
Epiphany
Jun 17, 2026
Dec 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.
2Debian
Gnome
2Debian Linux
Epiphany
Jun 17, 2026
Dec 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used, as demonstrated by a a page title.
2Debian
Gnome
2Debian Linux
Epiphany
Jun 17, 2026
Dec 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.
2Debian
Gnome
2Debian Linux
Epiphany
Jun 17, 2026
Dec 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Vis...Show more
XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-about:overview when a user visits an XSS payload page often enough to place that page on the Most Visited list.Show less
1Catfish Cms
1Catfish Cms
Jun 17, 2026
Dec 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admin/Index/addmenu.htmland then the .html file on the website that uses this editor (the file suffix is...Show more
Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admin/Index/addmenu.htmland then the .html file on the website that uses this editor (the file suffix is allowed).Show less
1Synacor
1Zimbra Collaboration Suite
Jun 17, 2026
Dec 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated attackers to execute arbitrary web scripts or HTML via a ho...Show more
A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated attackers to execute arbitrary web scripts or HTML via a host header injection.Show less
1Anchorcms
1Anchor Cms
Jun 17, 2026
Dec 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the adm...Show more
Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column to upload the title and content containing malicious code to achieve the purpose of obtaining the administrator cookie, thereby achieving other malicious operations.Show less
1Thruk
1Thruk
Jun 17, 2026
Dec 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Thruk before 2.44 allows XSS for a quick command.
1Lycheeorg
1Lychee
Jun 17, 2026
Dec 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php. The function exit will terminate the script and print the message to the user. The message will contain albumID which is...Show more
Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php. The function exit will terminate the script and print the message to the user. The message will contain albumID which is controlled by the user.Show less
1Yetiforce
1Yetiforce Customer Relationship Management
Jun 17, 2026
Dec 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Dolibarr
1Dolibarr
Jun 17, 2026
Dec 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box.
1Sofico
1Miles Rich Internet Application
Jun 17, 2026
Dec 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Sofico Miles RIA 2020.2 Build 127964T is affected by Stored Cross Site Scripting (XSS). An attacker with access to a user account of the RIA IT or the Fleet role can create a crafted work order in the damage reports sect...Show more
Sofico Miles RIA 2020.2 Build 127964T is affected by Stored Cross Site Scripting (XSS). An attacker with access to a user account of the RIA IT or the Fleet role can create a crafted work order in the damage reports section (or change existing work orders). The XSS payload is in the work order number.Show less
1Motorola
10T008 Firmware
T100 FirmwareT101 Firmware+7 more
Jun 17, 2026
Dec 15, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3.28.0.166; and T100,...Show more
Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3.28.0.166; and T100, T101, T102, and T103 before 2.6.0.180.Show less
1Verint
1Workforce Optimization
Jul 9, 2026
Dec 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.
1Genesys
1Workforce Management
Jul 9, 2026
Dec 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion) via the Time-off parameter.