← Back
CWE-79

47,713 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,713)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6C Ares Project
FedoraprojectNodejs+3 more
17C Ares
Enterprise LinuxEnterprise Linux Computer Node+14 more
Jun 17, 2026
Nov 23, 2021
N/A· v4
5.6 MEDIUM· v3
6.8 MEDIUM· v2
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The h...Show more
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.Show less
1Huawei
1Imaster Nce Fabric Firmware
Jun 17, 2026
Nov 23, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
There is a XSS injection vulnerability in iMaster NCE-Fabric V100R019C10. A module of the client does not verify the input sufficiently. Attackers can exploit this vulnerability by modifying input after logging onto the...Show more
There is a XSS injection vulnerability in iMaster NCE-Fabric V100R019C10. A module of the client does not verify the input sufficiently. Attackers can exploit this vulnerability by modifying input after logging onto the client. This may compromise the normal service of the client.Show less
1Shimo
1Document
Jun 17, 2026
Nov 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Shimo Document v2.0.1 contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the table content text field.
1Pekeupload Project
1Pekeupload
Jun 17, 2026
Nov 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
This affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains javascript code, the javascript code will be executed.
2Fedoraproject
Moodle
3Extra Packages For Enterprise Linux
FedoraMoodle
Jun 17, 2026
Nov 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflec...Show more
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.Show less
1Open Xchange
1Ox App Suite
Jun 17, 2026
Nov 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.
1Open Xchange
1Ox App Suite
Jun 17, 2026
Nov 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.
1Open Xchange
1Ox App Suite
Jun 17, 2026
Nov 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OX App Suite 7.10.5 allows XSS via an OX Chat system message.
1Open Xchange
1Ox App Suite
Jun 17, 2026
Nov 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering.
1Open Xchange
1Ox App Suite
Jun 17, 2026
Nov 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OX App Suite 7.10.5 allows XSS via an OX Chat room name.
1Open Xchange
1Ox App Suite
Jun 17, 2026
Nov 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.
1Open Xchange
1Ox App Suite
Jun 17, 2026
Nov 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.
1Qnap
1Ragic Cloud Db
Jun 17, 2026
Nov 20, 2021
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already disab...Show more
A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already disabled and removed Ragic Cloud DB from the QNAP App Center, pending a security patch from Ragic.Show less
1Backupbliss
1Backup Migration
Jun 17, 2026
Nov 19, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1.5 versions.
1Wpo365
1Wordpress + Azure Ad / Microsoft Office 365
Jun 17, 2026
Nov 19, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The “WPO365 | LOGIN” WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vul...Show more
The “WPO365 | LOGIN” WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper handling of dangerous content. This type of XSS vulnerability is exploited by submitting malicious script content to the application which is then retrieved and executed by other application users. The attacker could exploit this to conduct a range of attacks against users of the affected application such as session hijacking, account take over and accessing sensitive data. In this case, the XSS payload can be submitted by any anonymous user, the payload then renders and executes when a WordPress administrator authenticates and accesses the WordPress Dashboard. The injected payload can carry out actions on behalf of the administrator including adding other administrative users and changing application settings. This flaw could be exploited to ultimately provide full control of the affected system to the attacker.Show less
1Preview E Mails For Woocommerce Project
1Preview E Mails For Woocommerce
Jun 17, 2026
Nov 19, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Preview E-Mails for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the search_order parameter found in the ~/views/form.php file which allows attackers to inject arbitrary web script...Show more
The Preview E-Mails for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the search_order parameter found in the ~/views/form.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.6.8.Show less
1Microsoft
1Clarity
Jun 17, 2026
Nov 19, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
There is a Cross-Site Scripting vulnerability in Microsoft Clarity version 0.3. The XSS payload executes whenever the user changes the clarity configuration in Microsoft Clarity version 0.3. The payload is stored on the...Show more
There is a Cross-Site Scripting vulnerability in Microsoft Clarity version 0.3. The XSS payload executes whenever the user changes the clarity configuration in Microsoft Clarity version 0.3. The payload is stored on the configuring project Id page.Show less
1Getgrav
1Grav Plugin Admin
Jun 17, 2026
Nov 19, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Snipeitapp
1Snipe It
Jun 17, 2026
Nov 19, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Django Helpdesk Project
1Django Helpdesk
Jun 17, 2026
Nov 19, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')