CWE-79
47,713 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,713)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6C Ares Project FedoraprojectNodejs+3 more17C Ares Enterprise LinuxEnterprise Linux Computer Node+14 moreJun 17, 2026 Nov 23, 2021 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The h...Show more |
1Huawei 1Imaster Nce Fabric Firmware Jun 17, 2026 Nov 23, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 There is a XSS injection vulnerability in iMaster NCE-Fabric V100R019C10. A module of the client does not verify the input sufficiently. Attackers can exploit this vulnerability by modifying input after logging onto the...Show more |
Shimo Document v2.0.1 contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the table content text field. |
1Pekeupload Project 1Pekeupload Jun 17, 2026 Nov 22, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 This affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains javascript code, the javascript code will be executed. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 22, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflec...Show more |
OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message. |
OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL. |
OX App Suite 7.10.5 allows XSS via an OX Chat system message. |
OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering. |
OX App Suite 7.10.5 allows XSS via an OX Chat room name. |
OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature. |
OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file. |
A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already disab...Show more |
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1.5 versions. |
1Wpo365 1Wordpress + Azure Ad / Microsoft Office 365 Jun 17, 2026 Nov 19, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The “WPO365 | LOGIN” WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vul...Show more |
1Preview E Mails For Woocommerce Project 1Preview E Mails For Woocommerce Jun 17, 2026 Nov 19, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Preview E-Mails for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the search_order parameter found in the ~/views/form.php file which allows attackers to inject arbitrary web script...Show more |
There is a Cross-Site Scripting vulnerability in Microsoft Clarity version 0.3. The XSS payload executes whenever the user changes the clarity configuration in Microsoft Clarity version 0.3. The payload is stored on the...Show more |
grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
1Django Helpdesk Project 1Django Helpdesk Jun 17, 2026 Nov 19, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |