← Back
CWE-79

47,730 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
6Ipados
Iphone OsMacos+3 more
Jun 17, 2026
Sep 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5....Show more
Description: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. Processing maliciously crafted web content may lead to universal cross site scripting.Show less
1Deskpro
1Deskpro
Jun 17, 2026
Sep 8, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file feature on a manager profile due to lack of input validation.
1Smartertools
1Smartermail
Jun 17, 2026
Sep 8, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The application fails to sanitize email content, thus allowing one to inject HTML and/or JavaScript into a page that will then be processed and stored by th...Show more
SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The application fails to sanitize email content, thus allowing one to inject HTML and/or JavaScript into a page that will then be processed and stored by the application.Show less
1Phpwcms
1Phpwcms
Jun 17, 2026
Sep 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.
1Eyoucms
1Eyoucms
Jun 17, 2026
Sep 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the `title` parameter in bind_email function.
1Eyoucms
1Eyoucms
Jun 17, 2026
Sep 7, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject malicious code into `filename` param to trigger Reflected XSS.
1Cliniccases
1Cliniccases
Jun 17, 2026
Sep 7, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce arbitrary JavaScript to account parameters. The XSS payloads will execute in the browser of any user...Show more
Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce arbitrary JavaScript to account parameters. The XSS payloads will execute in the browser of any user who views the relevant content. This can result in account takeover via session token theft.Show less
1Cliniccases
1Cliniccases
Jun 17, 2026
Sep 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to introduce arbitrary JavaScript by crafting a malicious URL. This can result in account takeover via se...Show more
Multiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to introduce arbitrary JavaScript by crafting a malicious URL. This can result in account takeover via session token theft.Show less
1Nextcloud
1Circles
Jun 17, 2026
Sep 7, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. Due the str...Show more
Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. Due the strict Content-Security-Policy shipped with Nextcloud, this issue is not exploitable on modern browsers supporting Content-Security-Policy. It is recommended that the Nextcloud Circles application is upgraded to 0.21.3, 0.20.10 or 0.19.14 to resolve this issue. As a workaround users may use a browser that has support for Content-Security-Policy. A notable exemption is Internet Explorer which does not support CSP properly.Show less
1Remark
1Remark Html
Jun 17, 2026
Sep 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
remark-html is an open source nodejs library which compiles Markdown to HTML. In affected versions the documentation of remark-html has mentioned that it was safe by default. In practice the default was never safe and ha...Show more
remark-html is an open source nodejs library which compiles Markdown to HTML. In affected versions the documentation of remark-html has mentioned that it was safe by default. In practice the default was never safe and had to be opted into. That is, user input was not sanitized. This means arbitrary HTML can be passed through leading to potential XSS attacks. The problem has been patched in 13.0.2 and 14.0.1: `remark-html` is now safe by default, and the implementation matches the documentation. On older affected versions, pass `sanitize: true` if you cannot update.Show less
1Versa Networks
1Versa Director
Jun 17, 2026
Sep 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8. An attacker can use the administration web interface URL to create a XSS based attack.
1Deskpro
1Deskpro
Jun 17, 2026
Sep 7, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in social media links on a user profile due to lack of input validation.
1Moxa
12Oncell G3470a Lte Eu T Firmware
Oncell G3470a Lte Eu FirmwareTap 323 Eu Ct T Firmware+9 more
Jun 17, 2026
Sep 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3...Show more
Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.Show less
1Onyaktech Comments Pro Project
1Onyaktech Comments Pro
Jun 17, 2026
Sep 7, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add an XSS payload to the JSON request that will execute when users visit the page wi...Show more
An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. The comment posting functionality allows an attacker to add an XSS payload to the JSON request that will execute when users visit the page with the comment.Show less
1Otrs
1Otrs
Jun 17, 2026
Sep 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version...Show more
It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.Show less
1Bookstackapp
1Bookstack
Jun 17, 2026
Sep 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Bookstackapp
1Bookstack
Jun 17, 2026
Sep 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
1Keyword Meta Project
1Keyword Meta
Jun 17, 2026
Sep 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacki...Show more
The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacking any CSRF check, allowing attacker to make a logged in high privilege user save arbitrary setting via a CSRF attack.Show less
1Geminilabs
1Site Reviews
Jun 17, 2026
Sep 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is di...Show more
The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an admin, which could allow them to perform Cross-Site Scripting attacks when the unfiltered_html is disallowedShow less
1Wpfront
1Wpfront Notification Bar
Jun 17, 2026
Sep 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered...Show more
The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less