← Back
CWE-79

47,722 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,722)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Content Text Slider On Post Project
1Content Text Slider On Post
Nov 21, 2024
Nov 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Content text slider on post WordPress plugin before 6.9 does not sanitise and escape the Title and Message/Content settings, which could lead to Cross-Site Scripting issues
1Hp
2Futuresmart 4
Futuresmart 5
Jun 17, 2026
Oct 29, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Certain HP Enterprise LaserJet and PageWide MFPs may be vulnerable to stored cross site scripting (XSS).
1Hp
1Officejet 7110 Firmware
Jun 17, 2026
Oct 29, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS).
1Sysaid
1Sysaid
Jun 17, 2026
Oct 29, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.
1Tiki
1Tikiwiki Cms/groupware
Jun 17, 2026
Oct 28, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload u...Show more
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Add Event module.Show less
1Tiki
1Tikiwiki Cms/groupware
Jun 17, 2026
Oct 28, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted...Show more
TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categories.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload under the Create category module.Show less
1Mara Cms Project
1Mara Cms
Jun 17, 2026
Oct 28, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross site scripting (XSS) vulnerability in menuedit.php of Mara CMS 7.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
1Sourcecodester
1News247 Cms
Jun 17, 2026
Oct 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester News247 CMS 1.0 via the search function in articles.
1Hznuoj Project
1Hznuoj
Jun 17, 2026
Oct 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability was discovered in the OJ/admin-tool /cal_scores.php function of HZNUOJ v1.0.
1Getgrav
1Grav
Jun 17, 2026
Oct 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Cisco
4Firepower Management Center Virtual Appliance
Firepower Threat DefenseSecure Firewall Threat Defense+1 more
Aug 11, 2026
Oct 27, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For mo...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
4Firepower Management Center Virtual Appliance
Firepower Threat DefenseSecure Firewall Threat Defense+1 more
Aug 11, 2026
Oct 27, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For mo...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Phpgurukul
1Vehicle Parking Management System
Jun 17, 2026
Oct 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected version 1.0 is via the add-vehicle.php endpoint.
1Ibm
5Engineering Lifecycle Optimization
Rational Collaborative Lifecycle ManagementRational Doors Next Generation+2 more
Jun 17, 2026
Oct 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede...Show more
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Ibm
6Engineering Lifecycle Optimization
Engineering Workflow ManagementRational Collaborative Lifecycle Management+3 more
Jun 17, 2026
Oct 27, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede...Show more
IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199482.Show less
1Mybb
1Mybb
Jun 17, 2026
Oct 26, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not escaped properly.
1Froala
1Froala Editor
Jun 17, 2026
Oct 26, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross site scripting (XSS) vulnerability in the Insert Video function of Froala WYSIWYG Editor 3.1.0 allows attackers to execute arbitrary web scripts or HTML.
1Tibco
1Nimbus
Jun 17, 2026
Oct 26, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Web Reporting component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Stored Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user wi...Show more
The Web Reporting component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Stored Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: versions 10.4.0 and below.Show less
1Shopware
1Shopware
Jun 17, 2026
Oct 26, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This issue is patched in version 5.7.6. Two workarounds are available. Using the security plugin or addin...Show more
Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This issue is patched in version 5.7.6. Two workarounds are available. Using the security plugin or adding a particular following config to the `.htaccess` file will protect against cross-site scripting in this case. There is also a config for those using nginx as a server. The plugin and the configs can be found on the GitHub Security Advisory page for this vulnerability.Show less
6Drupal
FedoraprojectJqueryui+3 more
28Agile Plm
Agile Product Lifecycle ManagementApplication Express+25 more
Aug 25, 2026
Oct 26, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in...Show more
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the value of the `of` option from untrusted sources.Show less