← Back
CWE-79

47,724 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,724)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitlab
1Gitlab
Jun 17, 2026
Oct 5, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2....Show more
A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responsesShow less
1Gitlab
1Gitlab
Jun 17, 2026
Oct 5, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.
1Afian
1Filerun
Jul 5, 2026
Oct 5, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or edit action.
1Gitlab
1Gitlab
Jun 17, 2026
Oct 5, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbitrary JavaScript code on the victim's behalf.
1Afian
1Filerun
Jul 5, 2026
Oct 5, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity Logs.
1Xiuno
1Xiunobbs
Jun 17, 2026
Oct 4, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitebrief parameter.
1Xiuno
1Xiunobbs
Jun 17, 2026
Oct 4, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in the component /admin/?setting-base.htm of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via the sitename parameter.
1Xiuno
1Xiunobbs
Jun 17, 2026
Oct 4, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in the component install\install.sql of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via changing the doctype value to 0.
1Maccms
1Maccms
Jun 17, 2026
Oct 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Maccms 10 contains a cross-site scripting (XSS) vulnerability in the Editing function under the Member module. This vulnerability is exploited via a crafted payload in the nickname text field.
1Maccms
1Maccms
Jun 17, 2026
Oct 4, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and escalate privileges via a crafted payload.
1Bosch
2Rexroth Indramotion Mlc L20 Firmware
Rexroth Indramotion Mlc L40 Firmware
Jun 17, 2026
Oct 4, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client a manipulated URL.
1Gitlab
1Gitlab
Jun 17, 2026
Oct 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attack...Show more
A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious approval rule namesShow less
153kf
153kf
Jun 17, 2026
Oct 4, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross site scripting vulnerability in 53KF < 2.0.0.2 that allows for arbitrary code to be executed via crafted HTML statement inserted into chat window.
1Janeczku
1Calibre Web
Jun 17, 2026
Oct 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a vi...Show more
In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS will be triggered.Show less
1Gilacms
1Gila Cms
Jun 17, 2026
Oct 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, passwords or to run arbitrary code on a victim's browser.
1Icehrm
1Icehrm
Jun 17, 2026
Oct 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that allows for arbitrary execution of JavaScript commands.
1Bookingcore
1Booking Core
Jun 17, 2026
Oct 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Laravel Booking System Booking Core 2.0 is vulnerable to Cross Site Scripting (XSS). The Avatar upload in the My Profile section could be exploited to upload a malicious SVG file which contains Javascript. Now if another...Show more
Laravel Booking System Booking Core 2.0 is vulnerable to Cross Site Scripting (XSS). The Avatar upload in the My Profile section could be exploited to upload a malicious SVG file which contains Javascript. Now if another user/admin views the profile and clicks to view his avatar, an XSS will trigger.Show less
1Hkurl
1I Panel Administration System
Jun 17, 2026
Oct 4, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console and it is...Show more
A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console and it is possible to insert a vulnerable malicious button.Show less
1Webnus
1Modern Events Calendar Lite
Jun 17, 2026
Oct 4, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Modern Events Calendar Lite WordPress plugin before 5.22.2 does not escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even when th...Show more
The Modern Events Calendar Lite WordPress plugin before 5.22.2 does not escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Coinmarketstats
1Bitcoin / Altcoin Payment Gateway For Woocommerce
Jun 17, 2026
Oct 4, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting...Show more
The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issueShow less