CWE-79
47,728 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,728)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Revive Adserver 1Revive Adserver Jun 17, 2026 Sep 23, 2021 N/A· v4 7.1 HIGH· v3 4.3 MEDIUM· v2 Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force s...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Sep 23, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim into clicking a malicio...Show more |
1Cmsmadesimple 1Cms Made Simple Jun 17, 2026 Sep 22, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field. |
Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP. |
1Maianaffiliate 1Maianaffiliate Jun 17, 2026 Sep 22, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 MaianAffiliate v1.0 allows an authenticated administrative user to save an XSS to the database. |
jsuites is an open source collection of common required javascript web components. In affected versions users are subject to cross site scripting (XSS) attacks via clipboard content. jsuites is vulnerable to DOM based XS...Show more |
Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload. |
Cross Site Scripting (XSS) vlnerability exists in WUZHI CMS up to and including 4.1.0 in the config function in coreframe/app/attachment/libs/class/ckditor.class.php. |
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS. |
Cross-site scripting vulnerability due to the inadequate tag sanitization in GROWI versions v4.2.19 and earlier allows remote attackers to execute an arbitrary script on the web browser of the user who accesses a special...Show more |
The eID Easy WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error parameter found in the ~/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including...Show more |
The OptinMonster WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation in the load_previews function found in the ~/OMAPI/Output.php file which allows attackers to inject a...Show more |
Cross Site Scripting (XSS vulnerability exists in WUZHI CMS 4.1.0 via the mailbox username in index.php. |
1Ibm 1Tivoli Netcool/omnibus Webgui Jun 17, 2026 Sep 20, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more |
1Ibm 1Tivoli Netcool/omnibus Webgui Jun 17, 2026 Sep 20, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more |
1Ibm 1Tivoli Netcool/omnibus Webgui Jun 17, 2026 Sep 20, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more |
1Ibm 1Tivoli Netcool/omnibus Webgui Jun 17, 2026 Sep 20, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more |
1Ibm 1Tivoli Netcool/omnibus Webgui Jun 17, 2026 Sep 20, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more |
1Ibm 1Tivoli Netcool/omnibus Webgui Jun 17, 2026 Sep 20, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in...Show more |
1Ibm 1Tivoli Netcool/omnibus Webgui Jun 17, 2026 Sep 20, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in...Show more |