CWE-79
47,728 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,728)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
OpenSIS Community Edition version 8.0 is affected by a cross-site scripting (XSS) vulnerability in the TakeAttendance.php via the cp_id_miss_attn parameter. |
An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text. |
A cross-site scripting (XSS) vulnerability in the /banner/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML. |
A cross-site scripting (XSS) vulnerability in the /link/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML. |
1Ibm 1Jazz For Service Management Jun 17, 2026 Sep 23, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management 1.1.3.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially...Show more |
IBM Aspera Cloud is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials...Show more |
1Ibm 1Jazz For Service Management Jun 17, 2026 Sep 23, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intend...Show more |
1Ibm 1Jazz For Service Management Jun 17, 2026 Sep 23, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the...Show more |
1Ibm 1Jazz For Service Management Jun 17, 2026 Sep 23, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the...Show more |
1Ibm 1Jazz For Service Management Jun 17, 2026 Sep 23, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the...Show more |
1Ibm 1Jazz For Service Management Jun 17, 2026 Sep 23, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the...Show more |
1Ibm 1Jazz For Service Management Jun 17, 2026 Sep 23, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the...Show more |
1Ibm 1Jazz For Service Management Jun 17, 2026 Sep 23, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the...Show more |
1Ibm 1Jazz For Service Management Jun 17, 2026 Sep 23, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the...Show more |
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.11). Vulnerable parameter: &blockcountry_blockmessage. |
1Cusmin 1Absolutely Glamorous Custom Admin Jun 17, 2026 Sep 23, 2021 N/A· v4 8.2 HIGH· v3 3.5 LOW· v2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cusmin AGCA - Absolutely Glamorous Custom Admin (WordPress plugin) allows Stored XSS.This issue affects AGCA - Absolut...Show more |
1Ibm 2Jazz For Service Management Tivoli Netcool/omnibus WebguiJun 17, 2026 Sep 23, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Tivoli Netcool/OMNIbus_GUI and IBM Jazz for Service Management 1.1.3.10 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the...Show more |
IBM Sterling File Gateway 2.2.0.0 through 6.1.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential...Show more |
1Openvpn 1Openvpn Access Server Jun 17, 2026 Sep 23, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL. |
1Wordpress Popular Posts Project 1Wordpress Popular Posts Jun 17, 2026 Sep 23, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3). Vulnerable at &widget-wpp[2][post_type]. |