← Back
CWE-79

47,723 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,723)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Frontend Uploader Project
1Frontend Uploader
Jun 17, 2026
Oct 11, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which wi...Show more
The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directlyShow less
1Wp Html Author Bio Project
1Wp Html Author Bio
Jun 17, 2026
Oct 11, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the fronten...Show more
The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s.Show less
1Openwaygroup
1Way4
Jun 17, 2026
Oct 11, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OpenWay WAY4 ACS before 1.2.278-2693 allows XSS via the /way4acs/enroll action parameter.
2Fedoraproject
Mediawiki
2Fedora
Mediawiki
Jun 17, 2026
Oct 11, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Search results page.
1Django Unicorn
1Unicorn
Jun 17, 2026
Oct 11, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incomplete fix for CVE-2021-42053.
1Limesurvey
1Limesurvey
Jun 17, 2026
Oct 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.js and assets/scripts/uploader.js.
1Webtareas Project
1Webtareas
Jun 17, 2026
Oct 8, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against the pl...Show more
webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against the platform users and administrators. The issue affects every endpoint on the application because it is related on how each URL is echoed back on every response page.Show less
1Webtareas Project
1Webtareas
Jun 17, 2026
Oct 8, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
webTareas version 2.4 and earlier allows an authenticated user to store arbitrary web script or HTML by creating or editing a client name in the clients section, due to incorrect sanitization of user-supplied data and ac...Show more
webTareas version 2.4 and earlier allows an authenticated user to store arbitrary web script or HTML by creating or editing a client name in the clients section, due to incorrect sanitization of user-supplied data and achieve a Stored Cross-Site Scripting attack against the platform users and administrators. The affected endpoint is /clients/editclient.php, on the HTTP POST cn parameter.Show less
1Verint
1Workforce Optimization
Jun 17, 2026
Oct 8, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Verint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter.
1Tad Uploader Project
1Tad Uploader
Jun 17, 2026
Oct 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The new add subject parameter of Tad Uploader view book list function fails to filter special characters. Unauthenticated attackers can remotely inject JavaScript syntax and execute stored XSS attacks.
1Tadtools Project
1Tadtools
Jun 17, 2026
Oct 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
TadTools special page parameter does not properly restrict the input of specific characters, thus remote attackers can inject JavaScript syntax without logging in, and further perform reflective XSS attacks.
1Tad Book3 Project
1Tad Book3
Jun 17, 2026
Oct 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Tad Book3 editing book function does not filter special characters. Unauthenticated attackers can remotely inject JavaScript syntax and execute stored XSS attacks.
1Jeecms
1Jeecms X
Jun 17, 2026
Oct 7, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
JEECMS x1.1 contains a stored cross-site scripting (XSS) vulnerability in the component of /member-vipcenter.htm, which allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
1Zammad
1Zammad
Jun 17, 2026
Oct 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled.
1Zammad
1Zammad
Jun 17, 2026
Oct 7, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.
1Zammad
1Zammad
Jun 17, 2026
Oct 7, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to a Ticket.
1Ibm
1Sterling B2b Integrator
Jun 17, 2026
Oct 7, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality...Show more
IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199246.Show less
1Ibm
1Sterling B2b Integrator
Jun 17, 2026
Oct 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential...Show more
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199230.Show less
1Ibm
1Sterling File Gateway
Jun 17, 2026
Oct 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential...Show more
IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 197503.Show less
1Artica
1Integria Ims
Jun 17, 2026
Oct 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Integria IMS in its 5.0.92 version does not filter correctly some fields related to the login.php file. An attacker could exploit this vulnerability in order to perform a cross-site scripting attack (XSS).