← Back
CWE-79

47,713 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,713)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Nov 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.
1Airangel
5Hsmx App 1000 Firmware
Hsmx App 100 FirmwareHsmx App 20000 Firmware+2 more
Jun 17, 2026
Nov 10, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Airangel HSMX Gateway devices through 5.2.04 is vulnerable to stored Cross Site Scripting. XSS Payload is placed in the name column of the updates table using database access.
1Beeline
1Smart Box Firmware
Jun 17, 2026
Nov 10, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Beeline Smart Box 2.0.38 is vulnerable to Cross Site Scripting (XSS) via the choose_mac parameter to setup.cgi.
1Pega Sus
1Google For Jobs
Jun 17, 2026
Nov 10, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for TYPO3. The extension fails to properly encode user input for output in HTML context. A TYPO3 backen...Show more
An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for TYPO3. The extension fails to properly encode user input for output in HTML context. A TYPO3 backend user account is required to exploit the vulnerability.Show less
2Uclibc
Uclibc Ng Project
2Uclibc
Uclibc Ng
Jun 17, 2026
Nov 10, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames...Show more
In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.Show less
1Phoenixcontact
2Fl Mguard 1102 Firmware
Fl Mguard 1105 Firmware
Jun 17, 2026
Nov 10, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 a user with high privileges can inject HTML code (XSS) through web-based management or the REST API with a manipulated certificate file.
1Publify Project
1Publify
Jun 17, 2026
Nov 10, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file.
1Publify Project
1Publify
Jun 17, 2026
Nov 10, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article.
1Microsoft
1Power Bi Report Server
Aug 19, 2026
Nov 10, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directl...Show more
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities together, an attacker is able to upload malicious Power BI templates files to the server using the victim's session and run scripts in the security context of the user and perform privilege escalation in case the victim has admin privileges when the victim access one of the HTML files present in the malicious Power BI template uploaded. The security update addresses the vulnerability by helping to ensure that Power BI Report Server properly sanitize file uploads.Show less
1Thruk
1Thruk
Jun 17, 2026
Nov 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Thruk 2.40-2 allows /thruk/#cgi-bin/extinfo.cgi?type=2&host={HOSTNAME]&service={SERVICENAME]&backend={BACKEND] Reflected XSS via the host or service parameter. An attacker could inject arbitrary JavaScript into extinfo.c...Show more
Thruk 2.40-2 allows /thruk/#cgi-bin/extinfo.cgi?type=2&host={HOSTNAME]&service={SERVICENAME]&backend={BACKEND] Reflected XSS via the host or service parameter. An attacker could inject arbitrary JavaScript into extinfo.cgi. The malicious payload would be triggered every time an authenticated user browses the page containing it.Show less
1Thruk
1Thruk
Jun 17, 2026
Nov 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status.cgi. The payload would be triggered eve...Show more
Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title parameter. An attacker could inject arbitrary JavaScript into status.cgi. The payload would be triggered every time an authenticated user browses the page containing it.Show less
1Jetbrains
1Hub
Jun 17, 2026
Nov 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains Hub before 2021.1.13690, stored XSS is possible.
1Jetbrains
1Teamcity
Jun 17, 2026
Nov 9, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In JetBrains TeamCity before 2021.1.2, stored XSS is possible.
1Jetbrains
1Teamcity
Jun 17, 2026
Nov 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.
1Jetbrains
1Youtrack
Jun 17, 2026
Nov 9, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.
1Jetbrains
1Youtrack
Jun 17, 2026
Nov 9, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.
1Hp
2Futuresmart 3
Futuresmart 4
Jun 17, 2026
Nov 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A potential security vulnerability has been identified for certain HP printers and MFPs that would allow redirection page Cross-Site Scripting in a client’s browser by clicking on a third-party malicious link.
1Casap Automated Enrollment System Project
1Casap Automated Enrollment System
Jun 17, 2026
Nov 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester CASAP Automated Enrollment System 1.0 via the (1) user_username and (2) category parameters in save_class.php, the (3) firstname, (4) class, and...Show more
Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester CASAP Automated Enrollment System 1.0 via the (1) user_username and (2) category parameters in save_class.php, the (3) firstname, (4) class, and (5) status parameters in student_table.php, the (6) category and (7) class_name parameters in add_class1.php, the (8) fname, (9) mname,(10) lname, (11) address, (12) class, (13) gfname, (14) gmname, (15) glname, (16) rship, (17) status, (18) transport, and (19) route parameters in add_student.php, the (20) fname, (21) mname, (22) lname, (23) address, (24) class, (25) fgname, (26) gmname, (27) glname, (28) rship, (29) status, (30) transport, and (31) route parameters in save_stud.php,the (32) status, (33) fname, and (34) lname parameters in add_user.php, the (35) username, (36) firstname, and (37) status parameters in users.php, the (38) fname, (39) lname, and (40) status parameters in save_user.php, and the (41) activity_log, (42) aprjun, (43) class, (44) janmar, (45) Julsep,(46) octdec, (47) Students and (48) users parameters in table_name.Show less
1Tailor Management System Project
1Tailor Management System
Jun 17, 2026
Nov 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester Tailor Management 1.0 via the (1) eid parameter in (a) partedit.php and (b) customeredit.php, the (2) id parameter in (a) editmeasurement.php an...Show more
Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester Tailor Management 1.0 via the (1) eid parameter in (a) partedit.php and (b) customeredit.php, the (2) id parameter in (a) editmeasurement.php and (b) addpayment.php, and the (3) error parameter in index.php.Show less
1Vfront
1Vfront
Jun 17, 2026
Nov 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple Cross Site Scripting (XSS) vulnerabilities exist in VFront 0.99.5 via the (1) s parameter in search_all.php and the (2) msg parameter in add.attach.php.