← Back
CWE-79

47,728 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,728)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pi Hole
1Web Interface
Jun 17, 2026
Sep 17, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Activefusions
1Order Status Batch Change
Jun 17, 2026
Sep 17, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Order Status Batch Change Plug-in (for EC-CUBE 3.0 series) all versions allows a remote attacker to inject an arbitrary script via unspecified vectors.
1Shiro8
1List (order Management) Item Change
Jun 17, 2026
Sep 17, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in List (order management) item change plug-in (for EC-CUBE 3.0 series) Ver.1.1 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors.
1Os4ed
1Opensis
Jun 17, 2026
Sep 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OpenSIS Community Edition version <= 7.6 is affected by a reflected XSS vulnerability in EmailCheck.php via the "opt" parameter.
1Rgcms Project
1Rgcms
Jun 17, 2026
Sep 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in RGCMS v1.06 allows attackers to obtain the administrator's cookie via a crafted payload in the Name field under the Message Board module
1Sap
1Businessobjects Business Intelligence
Jun 17, 2026
Sep 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode user controlled inputs and therefore an authorized attacker can exploit a XSS vulnerability, leading...Show more
SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode user controlled inputs and therefore an authorized attacker can exploit a XSS vulnerability, leading to non-permanently deface or modify displayed content from a Web site.Show less
1Sap
1Cloud Connector
Jun 17, 2026
Sep 15, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with Administrator rights, to include malicious codes that get stored in the database, and when accessed, coul...Show more
SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with Administrator rights, to include malicious codes that get stored in the database, and when accessed, could be executed in the application, resulting in Stored Cross-Site Scripting.Show less
1Sap
1Netweaver Development Infrastructure
Jun 17, 2026
Sep 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
NWDI Notification Service versions - 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.SAP NetWeaver Development Infrastructure Notification Serv...Show more
NWDI Notification Service versions - 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.SAP NetWeaver Development Infrastructure Notification Service allows a threat actor to send crafted scripts to a victim. If the victim has an active session when the crafted script gets executed, the threat actor could compromise information in victims session, and gain access to some sensitive information also.Show less
1Prasathmani
1Tiny File Manager
Jun 17, 2026
Sep 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and javascript in its name. A malicious user can upload a file with...Show more
A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and javascript in its name. A malicious user can upload a file with a malicious filename containing javascript code and it will run on any user browser when they access the server.Show less
18x8
1Jitsi Meet
Jun 17, 2026
Sep 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped. There...Show more
Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cross-site scripting via injecting properties into JSON objects that were not properly escaped. There are no known incidents related to this vulnerability being exploited in the wild. This issue is fixed in Jitsi Meet version 2.0.6173. There are no known workarounds aside from upgrading.Show less
1Sitasoftware
1Azurcms
Jun 17, 2026
Sep 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities exist in SITA Software Azur CMS 1.2.3.1 and earlier, which allows remote attackers to inject arbitrary web script or HTML via the (1) NOM_CLI , (2) ADRESSE , (3) ADRESS...Show more
Multiple cross-site scripting (XSS) vulnerabilities exist in SITA Software Azur CMS 1.2.3.1 and earlier, which allows remote attackers to inject arbitrary web script or HTML via the (1) NOM_CLI , (2) ADRESSE , (3) ADRESSE2, (4) LOCALITE parameters to /eshop/products/json/aouCustomerAdresse; and the (5) nom_liste parameter to /eshop/products/json/addCustomerFavorite.Show less
1Webuzo
1Webuzo
Jun 17, 2026
Sep 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross Site Scriptiong (XSS) vulnerability exists in the admin panel in Webuzo < 2.9.0 via an HTTP request to a non-existent page, which is activated by administrators viewing the "Error Log" page. An attacker can lever...Show more
A Cross Site Scriptiong (XSS) vulnerability exists in the admin panel in Webuzo < 2.9.0 via an HTTP request to a non-existent page, which is activated by administrators viewing the "Error Log" page. An attacker can leverage this to achieve Unauthenticated Remote Code Execution via the "Cron Jobs" functionality of Webuzo.Show less
1It Economics
1Techradar
Jun 17, 2026
Sep 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The TechRadar app 1.1 for Confluence Server allows XSS via the Title field of a Radar.
1Nagios
1Nagios Xi
Jun 17, 2026
Sep 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.
1S Cms
1S Cms
Jun 17, 2026
Sep 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) in S-CMS build 20191014 and earlier allows remote attackers to execute arbitrary code via the 'Site Title' parameter of the component '/data/admin/#/app/config/'.
1Wenkucms Project
1Wenkucms
Jun 17, 2026
Sep 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter for the component '/index.php?m=ucenter&a=index'.
1Ari Soft
1Ari Adminer
Jun 17, 2026
Sep 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter of the 'Add New Connections' component when the 'save()' function is called.
1Jflyfox
1Jfinal Cms
Jun 17, 2026
Sep 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.
1Pdftron
1Webviewer Ui
Jun 17, 2026
Sep 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PDFTron's WebViewer UI 8.0 or below renders dangerous URLs as hyperlinks in supported documents, including JavaScript URLs, allowing the execution of arbitrary JavaScript code.
1Microsoft
1Dynamics 365 Business Central
Aug 10, 2026
Sep 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability