CWE-79
47,730 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,730)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Apple 6Ipados Iphone OsMacos+3 moreJun 17, 2026 Sep 8, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5....Show more |
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file feature on a manager profile due to lack of input validation. |
SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The application fails to sanitize email content, thus allowing one to inject HTML and/or JavaScript into a page that will then be processed and stored by th...Show more |
phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php. |
A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the `title` parameter in bind_email function. |
Eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject malicious code into `filename` param to trigger Reflected XSS. |
Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce arbitrary JavaScript to account parameters. The XSS payloads will execute in the browser of any user...Show more |
Multiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to introduce arbitrary JavaScript by crafting a malicious URL. This can result in account takeover via se...Show more |
Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. Due the str...Show more |
remark-html is an open source nodejs library which compiles Markdown to HTML. In affected versions the documentation of remark-html has mentioned that it was safe by default. In practice the default was never safe and ha...Show more |
1Versa Networks 1Versa Director Jun 17, 2026 Sep 7, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8. An attacker can use the administration web interface URL to create a XSS based attack. |
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in social media links on a user profile due to lack of input validation. |
1Moxa 12Oncell G3470a Lte Eu T Firmware Oncell G3470a Lte Eu FirmwareTap 323 Eu Ct T Firmware+9 moreJun 17, 2026 Sep 7, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3...Show more |
1Onyaktech Comments Pro Project 1Onyaktech Comments Pro Jun 17, 2026 Sep 7, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add an XSS payload to the JSON request that will execute when users visit the page wi...Show more |
It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version...Show more |
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
1Keyword Meta Project 1Keyword Meta Jun 17, 2026 Sep 6, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacki...Show more |
The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is di...Show more |
1Wpfront 1Wpfront Notification Bar Jun 17, 2026 Sep 6, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered...Show more |