← Back
CWE-79

47,722 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,722)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tempura Project
1Tempura
Jun 17, 2026
Nov 3, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is returned without being escaped/sanitized, leading to a potential Cross-Site Scripting vulnerability.
1Ed01 Cms Project
1Ed01 Cms
Jun 17, 2026
Nov 3, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ED01-CMS v1.0 was discovered to contain a reflective cross-site scripting (XSS) vulnerability in the component sposts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payloa...Show more
ED01-CMS v1.0 was discovered to contain a reflective cross-site scripting (XSS) vulnerability in the component sposts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Post title or Post content fields.Show less
1Chamilo
1Chamilo Lms
Jun 17, 2026
Nov 3, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/herself and social network friends.
1Wdja
1Wdja Cms
Jun 17, 2026
Nov 3, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain escalated privileges, via the backurl parameter to /php/passport/index.php.
1Librenms
1Librenms
Jun 17, 2026
Nov 3, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
LibreNMS through 21.10.2 allows XSS via a widget title.
1Artica
1Pandora Fms
Jul 9, 2026
Nov 3, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.
1Mahara
1Mahara
Jun 17, 2026
Nov 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, certain tag syntax could be used for XSS, such as via a SCRIPT element.
1Fortinet
1Fortiportal
Jun 17, 2026
Nov 2, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a single low-privileged user to induce a denial of service via multiple HTTP requests.
1Php Fusion
1Phpfusion
Jun 17, 2026
Nov 2, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature.
1Zibbs Project
1Zibbs
Jun 17, 2026
Nov 2, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Cross site scripting (XSS) vulnerability in application/controllers/AdminController.php in xujinliang zibbs 1.0, allows attackers to execute arbitrary code via the bbsmeta parameter.
1Zibbs Project
1Zibbs
Jun 17, 2026
Nov 2, 2021
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Cross site scripting (XSS) vulnerability in xujinliang zibbs 1.0, allows attackers to execute arbitrary code via the route parameter to index.php.
1Fortinet
1Forticlient Enterprise Management Server
Jun 17, 2026
Nov 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An improper neutralization of input vulnerability [CWE-79] in FortiClientEMS versions 6.4.1 and below and 6.2.9 and below may allow a remote authenticated attacker to inject malicious script/tags via the name parameter o...Show more
An improper neutralization of input vulnerability [CWE-79] in FortiClientEMS versions 6.4.1 and below and 6.2.9 and below may allow a remote authenticated attacker to inject malicious script/tags via the name parameter of various sections of the server.Show less
1Fortinet
1Fortianalyzer
Jun 17, 2026
Nov 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiAnalyzer version 6.0.6 and below, version 6.4.4 allows attacker to execute unauthorized code or commands via specifi...Show more
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiAnalyzer version 6.0.6 and below, version 6.4.4 allows attacker to execute unauthorized code or commands via specifically crafted requests to the web GUI.Show less
1Ibm
1Infosphere Information Server
Jun 17, 2026
Nov 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Elkarbackup
1Elkarbackup
Jun 17, 2026
Nov 2, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability in ElkarBackup 1.3.3, allows attackers to execute arbitrary code via the name parameter to the add client feature.
1Dynpg
1Dynpg
Jul 9, 2026
Nov 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability in DynPG 4.9.1, allows authenticated attackers to execute arbitrary code via the groupname.
1Vaadin
2Vaadin
Vaadin Menu Bar
Jun 17, 2026
Nov 2, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Missing output sanitization in test sources in org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2.0 (Vaadin 14.0.0 through 14.4.4) allows remote attackers to execute malicious JavaScript in browser...Show more
Missing output sanitization in test sources in org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2.0 (Vaadin 14.0.0 through 14.4.4) allows remote attackers to execute malicious JavaScript in browser by opening crafted URLShow less
1Atlassian
1Jira Software Data Center
Jun 17, 2026
Nov 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Associated Projects feature (/secur...Show more
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Associated Projects feature (/secure/admin/AssociatedProjectsForCustomField.jspa). The affected versions are before version 8.5.19, from version 8.6.0 before 8.13.11, and from version 8.14.0 before 8.19.1.Show less
1Supsystic
1Easy Google Maps
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/modules/marker_groups/views/tpl/mgrEditMarker...Show more
The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/modules/marker_groups/views/tpl/mgrEditMarkerGroup.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 1.9.33. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.Show less
1Bracketspace
1Notification
Jun 17, 2026
Nov 1, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/classes/Utils/Settings.php file which made it...Show more
The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/src/classes/Utils/Settings.php file which made it possible for attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 7.2.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.Show less