CWE-79
47,722 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,722)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for reflected XSS attacks due to the operatorlocale GET parameter not being sanitized. This issue impacts...Show more |
1Mcafee 1Epolicy Orchestrator Jun 17, 2026 Oct 22, 2021 N/A· v4 4.8 MEDIUM· v3 4.3 MEDIUM· v2 Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrators to inject arbitrary web script or HTML via a specific parameter where the administrator's entries...Show more |
Stored Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's en...Show more |
Sulu is an open-source PHP content management system based on the Symfony framework. In versions before 1.6.43 are subject to stored cross site scripting attacks. HTML input into Tag names is not properly sanitized. Only...Show more |
Reflected Cross-Site Scripting (XSS) vulnerability in WordPress Ivory Search plugin (versions <= 4.6.6). Vulnerable parameter: &post. |
"HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability" |
The Leaky Paywall WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via the ~/class.php file which allowed attackers with administrative user access to in...Show more |
1Content Staging Project 1Content Staging Jun 17, 2026 Oct 21, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Content Staging WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via several parameters that are echo'd out via the ~/templates/settings.php file which a...Show more |
1Awesomemotive 1Easy Digital Downloads Jun 17, 2026 Oct 21, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end_date parameters found in the ~/includes/admin/payments/class-payments-table.php file which allows a...Show more |
The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom_profile parameter found in the ~/inc/admin/views/backend-user-profile.php file which allowed attack...Show more |
The Simple Job Board WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $job_board_privacy_policy_label variable echo'd out via the ~/admin/settings/class-simple-job-board-s...Show more |
1Solarwinds 1Database Performance Analyzer Jun 17, 2026 Oct 21, 2021 N/A· v4 4.7 MEDIUM· v3 2.6 LOW· v2 This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would ne...Show more |
1Solarwinds 1Access Rights Manager Jun 17, 2026 Oct 21, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available. |
WP Mailster 1.6.18.0 allows XSS when a victim opens a mail server's details in the mst_servers page, for a crafted server_host, server_name, or connection_parameter parameter. |
1Alfresco 2Community Share ShareJun 17, 2026 Oct 21, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in Hyland org.alfresco:share through 7.0.0.2 and org.alfresco:community-share through 7.0. An evasion of the XSS filter for HTML input validation in the Alfresco Share User Interface leads to stor...Show more |
1Cisco 1Identity Services Engine Jun 17, 2026 Oct 21, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For...Show more |
A vulnerability in the web-based management interface of Cisco Tetration could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack on an affected system. This vulnerability exist...Show more |
1Cisco 1Telepresence Management Suite Jun 17, 2026 Oct 21, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of t...Show more |
1Cisco 1Identity Services Engine Jun 17, 2026 Oct 21, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For...Show more |
IBM QRadar Advisor 2.5 through 2.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to...Show more |