CWE-79
47,722 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,722)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Content Text Slider On Post Project 1Content Text Slider On Post Nov 21, 2024 Nov 1, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Content text slider on post WordPress plugin before 6.9 does not sanitise and escape the Title and Message/Content settings, which could lead to Cross-Site Scripting issues |
Certain HP Enterprise LaserJet and PageWide MFPs may be vulnerable to stored cross site scripting (XSS). |
A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS). |
SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication. |
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload u...Show more |
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted...Show more |
A cross site scripting (XSS) vulnerability in menuedit.php of Mara CMS 7.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. |
1Sourcecodester 1News247 Cms Jun 17, 2026 Oct 28, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross Site Scripting (XSS) vulnerability exists in Sourcecodester News247 CMS 1.0 via the search function in articles. |
A cross-site scripting (XSS) vulnerability was discovered in the OJ/admin-tool /cal_scores.php function of HZNUOJ v1.0. |
grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
1Cisco 4Firepower Management Center Virtual Appliance Firepower Threat DefenseSecure Firewall Threat Defense+1 moreAug 11, 2026 Oct 27, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For mo...Show more |
1Cisco 4Firepower Management Center Virtual Appliance Firepower Threat DefenseSecure Firewall Threat Defense+1 moreAug 11, 2026 Oct 27, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For mo...Show more |
1Phpgurukul 1Vehicle Parking Management System Jun 17, 2026 Oct 27, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected version 1.0 is via the add-vehicle.php endpoint. |
1Ibm 5Engineering Lifecycle Optimization Rational Collaborative Lifecycle ManagementRational Doors Next Generation+2 moreJun 17, 2026 Oct 27, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede...Show more |
1Ibm 6Engineering Lifecycle Optimization Engineering Workflow ManagementRational Collaborative Lifecycle Management+3 moreJun 17, 2026 Oct 27, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede...Show more |
MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly. |
A cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor 3.1.0 allows attackers to execute arbitrary web scripts or HTML. |
The Web Reporting component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Stored Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user wi...Show more |
Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This issue is patched in version 5.7.6. Two workarounds are available. Using the security plugin or addin...Show more |
6Drupal FedoraprojectJqueryui+3 more28Agile Plm Agile Product Lifecycle ManagementApplication Express+25 moreAug 25, 2026 Oct 26, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in...Show more |