← Back
CWE-79

47,692 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,692)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kentico
1Xperience
Jun 17, 2026
Dec 3, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Kentico Xperience CMS version 13.0 – 13.0.43 is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the applicatio...Show more
The Kentico Xperience CMS version 13.0 – 13.0.43 is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper handling of dangerous content. This type of XSS vulnerability is exploited by submitting malicious script content to the application which is then retrieved and executed by other application users. The attacker could exploit this to conduct a range of attacks against users of the affected application such as session hijacking, account take over and accessing sensitive data.Show less
1Dzzoffice
1Dzzoffice
Jun 17, 2026
Dec 3, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of the exit function is printed for the user via exit(json_encode($return)).
1Taogogo
1Taocms
Jun 17, 2026
Dec 2, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Taocms v2.5Beta5 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Management column.
1Cbads
1Clickbank Affiliate Ads
Nov 21, 2024
Dec 2, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not escape its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
1Cbads
1Clickbank Affiliate Ads
Nov 21, 2024
Dec 2, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escapi...Show more
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored Cross-Site Scripting issuesShow less
1Craftercms
1Crafter Cms
Jun 17, 2026
Dec 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site.
1Thinkphp Bjyblog Project
1Thinkphp Bjyblog
Jun 17, 2026
Dec 2, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseController.class.php. The exit function terminates the script and prints a message to the user that contains...Show more
thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseController.class.php. The exit function terminates the script and prints a message to the user that contains $_SERVER['HTTP_HOST'].Show less
1Nzedb Project
1Nzedb
Jun 17, 2026
Dec 2, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
nZEDb v0.4.20 is affected by a Cross Site Scripting (XSS) vulnerability in www/pages/api.php. The exit function will terminate the script and print the message which has the input $_GET['t'].
1Haschek
1Pictshare
Jun 17, 2026
Dec 2, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
pictshare v1.5 is affected by a Cross Site Scripting (XSS) vulnerability in api/info.php. The exit function will terminate the script and print the message which has $_REQUEST['hash'].
1Zerodream
1Sakurapanel
Jun 17, 2026
Dec 2, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SakuraPanel v1.0.1.1 is affected by a Cross Site Scripting (XSS) vulnerability in /master/core/PostHandler.php. The exit function will terminate the script and print the message $data['proxy_name'].
1Pixelite
1Events Manager
Jun 17, 2026
Dec 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues
1Phpgurukul
1Hostel Management System
Jun 17, 2026
Dec 1, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Dec 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti...Show more
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 205281.Show less
1Chamilo
1Chamilo
Jul 9, 2026
Dec 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.
1Manage Project
1Manage
Jun 17, 2026
Dec 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
manage (last update Oct 24, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in Application/Home/Controller/GoodsController.class.php. The exit function will terminate the script and print a message which...Show more
manage (last update Oct 24, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in Application/Home/Controller/GoodsController.class.php. The exit function will terminate the script and print a message which have values from $_POST.Show less
1Librenms
1Librenms
Jun 17, 2026
Dec 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/forms/poller-groups.inc.php.
1Librenms
1Librenms
Jun 17, 2026
Dec 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/common/alert-log.inc.php.
1Okfn
1Ckan
Jun 17, 2026
Dec 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability via SVG file upload of users’ profile picture. This allows low privileged application users to store malicious scripts in their profile picture....Show more
In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability via SVG file upload of users’ profile picture. This allows low privileged application users to store malicious scripts in their profile picture. These scripts are executed in a victim’s browser when they open the malicious profile pictureShow less
1Yurunproxy Project
1Yurunproxy
Jun 17, 2026
Dec 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
YurunProxy v0.01 is affected by a Cross Site Scripting (XSS) vulnerability in src/Client.php. The exit function will terminate the script and print a message which have values from the socket_read.
1Kimai2 Project
1Kimai2
Jun 17, 2026
Dec 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')