CWE-79
47,728 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,728)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
peertube is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
1F5 14Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+11 moreJun 17, 2026 Sep 14, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an...Show more |
Cross Site Scripting (XSS) vulnerability exists in the admin panel in Beego v2.0.1 via the URI path in an HTTP request, which is activated by administrators viewing the "Request Statistics" page. |
1Tibco 3Webfocus Client Webfocus InstallerWebfocus Reporting ServerJun 17, 2026 Sep 14, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The WebFOCUS Reporting Server and WebFOCUS Client components of TIBCO Software Inc.'s TIBCO WebFOCUS Client, TIBCO WebFOCUS Installer, and TIBCO WebFOCUS Reporting Server contain easily exploitable Stored and Reflected C...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 Sep 14, 2021 N/A· v4 9.0 CRITICAL· v3 3.5 LOW· v2 On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of th...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 Sep 14, 2021 N/A· v4 9.6 CRITICAL· v3 4.3 MEDIUM· v2 On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacke...Show more |
A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows attackers to steal administrator and user cookies via crafted payloads in the text fields for Chin...Show more |
1Ibm 1Financial Transaction Manager Jun 17, 2026 Sep 14, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Advanced Web Application Firewall+8 moreJun 17, 2026 Sep 14, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a DOM based cross-site scripting (XSS) vulnerability exists in an undisclosed pa...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Sep 14, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The SAP BusinessObjects BI Platform version - 420 allows an attacker, who has basic access to the application, to inject a malicious script while creating a new module document, file, or folder. When another user visits...Show more |
Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a Reflected Cross-Site Scripting (XSS) vulnerability through phishing an...Show more |
Under certain conditions, SAP Contact Center - version 700, does not sufficiently encode user-controlled inputs. This allows an attacker to exploit a Reflected Cross-Site Scripting (XSS) vulnerability when creating a new...Show more |
Under certain conditions, SAP Contact Center - version 700,does not sufficiently encode user-controlled inputs and persists in them. This allows an attacker to exploit a Stored Cross-Site Scripting (XSS) vulnerability wh...Show more |
In CS-Cart version 4.11.1, it is possible to induce copy-paste XSS by manipulating the "post description" filed in the blog post creation page. |
1Sap 1Netweaver Enterprise Portal Jun 17, 2026 Sep 14, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 SAP NetWeaver Enterprise Portal versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user related data, resulting in Stored Cross-Site Scripting (XSS) vulnerability. This would allow an attac...Show more |
1Motopress 1Timetable And Event Schedule Jun 17, 2026 Sep 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privilege users such as author to perform XSS attacks against frontend and back...Show more |
1Ticket System 1Wordpress Advanced Ticket System Jun 17, 2026 Sep 13, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The WordPress Advanced Ticket System, Elite Support Helpdesk WordPress plugin before 1.0.64 does not sanitize or escape form values before saving to the database or when outputting, which allows high privilege users to p...Show more |
1Stratospheredigital 1Wp Courses Lms Jun 17, 2026 Sep 13, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The WP Courses LMS WordPress plugin before 2.0.44 does not sanitise its Video Embed Code, allowing malicious code to be injected in it by high privilege users, even when the unfiltered_html capability is disallowed, whic...Show more |