← Back
CWE-79

47,728 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,728)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Revive Adserver
1Revive Adserver
Jun 17, 2026
Sep 23, 2021
N/A· v4
7.1 HIGH· v3
4.3 MEDIUM· v2
Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force s...Show more
Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a specific account.Show less
1Vmware
2Cloud Foundation
Vcenter Server
Jun 17, 2026
Sep 23, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim into clicking a malicio...Show more
The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim into clicking a malicious link.Show less
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Sep 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field.
1Mattermost
1Mattermost
Jun 17, 2026
Sep 22, 2021
N/A· v4
6.1 MEDIUM· v3
2.6 LOW· v2
Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.
1Maianaffiliate
1Maianaffiliate
Jun 17, 2026
Sep 22, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
MaianAffiliate v1.0 allows an authenticated administrative user to save an XSS to the database.
1Jsuites
1Jsuites
Jun 17, 2026
Sep 21, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
jsuites is an open source collection of common required javascript web components. In affected versions users are subject to cross site scripting (XSS) attacks via clipboard content. jsuites is vulnerable to DOM based XS...Show more
jsuites is an open source collection of common required javascript web components. In affected versions users are subject to cross site scripting (XSS) attacks via clipboard content. jsuites is vulnerable to DOM based XSS if the user can be tricked into copying _anything_ from a malicious and pasting it into the html editor. This is because a part of the clipboard content is directly written to `innerHTML` allowing for javascript injection and thus XSS. Users are advised to update to version 4.9.11 to resolve.Show less
1Manageengine
1Opmanager
Jun 17, 2026
Sep 21, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.
1Wuzhicms
1Wuzhicms
Jun 17, 2026
Sep 21, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vlnerability exists in WUZHI CMS up to and including 4.1.0 in the config function in coreframe/app/attachment/libs/class/ckditor.class.php.
1Cloudron
1Cloudron
Jun 17, 2026
Sep 21, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
1Weseek
1Growi
Jun 17, 2026
Sep 21, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability due to the inadequate tag sanitization in GROWI versions v4.2.19 and earlier allows remote attackers to execute an arbitrary script on the web browser of the user who accesses a special...Show more
Cross-site scripting vulnerability due to the inadequate tag sanitization in GROWI versions v4.2.19 and earlier allows remote attackers to execute an arbitrary script on the web browser of the user who accesses a specially crafted page.Show less
1Eideasy
1Eid Easy
Jun 17, 2026
Sep 20, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The eID Easy WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error parameter found in the ~/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including...Show more
The eID Easy WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error parameter found in the ~/admin.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.6.Show less
1Optinmonster
1Optinmonster
Jun 17, 2026
Sep 20, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The OptinMonster WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation in the load_previews function found in the ~/OMAPI/Output.php file which allows attackers to inject a...Show more
The OptinMonster WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation in the load_previews function found in the ~/OMAPI/Output.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.6.0.Show less
1Wuzhicms
1Wuzhicms
Jun 17, 2026
Sep 20, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS vulnerability exists in WUZHI CMS 4.1.0 via the mailbox username in index.php.
1Ibm
1Tivoli Netcool/omnibus Webgui
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204348.Show less
1Ibm
1Tivoli Netcool/omnibus Webgui
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204347.Show less
1Ibm
1Tivoli Netcool/omnibus Webgui
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204346.Show less
1Ibm
1Tivoli Netcool/omnibus Webgui
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204345.Show less
1Ibm
1Tivoli Netcool/omnibus Webgui
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended...Show more
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204343.Show less
1Ibm
1Tivoli Netcool/omnibus Webgui
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in...Show more
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204270.Show less
1Ibm
1Tivoli Netcool/omnibus Webgui
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the in...Show more
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 204269.Show less