CWE-79
47,733 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,733)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content. |
A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via the Segment Name parameter. |
A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "or Expiring Between" parame...Show more |
1Paste Markdown Project 1Paste Markdown Jun 17, 2026 Aug 12, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 @github/paste-markdown is an npm package for pasting markdown objects. A self Cross-Site Scripting vulnerability exists in the @github/paste-markdown before version 0.3.4. If the clipboard data contains the string `<tabl...Show more |
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
1Microsoft 2Dynamics 365 Business Central Dynamics NavAug 10, 2026 Aug 12, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Microsoft Dynamics Business Central Cross-site Scripting Vulnerability |
Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php. |
Cross Site Scripting (XSS) vulnerability exists in bycms v3.0.4 via the title parameter in the edit function in Document.php. |
Cross Site Scripting (XSS) vulnerability exists in DamiCMS v6.0.6 via the title parameter in the doadd function in LabelAction.class.php. |
Cross Site Scripting (XSS) vulnerability exists in UKCMS v1.1.10 via data in the index function in Single.php |
3Ckeditor FedoraprojectOracle10Application Express Banking Party ManagementCkeditor+7 moreJun 17, 2026 Aug 12, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allo...Show more |
3Ckeditor FedoraprojectOracle13Application Express Banking Party ManagementCkeditor+10 moreJun 17, 2026 Aug 12, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse un...Show more |
Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php. |
Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php. |
Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7. |
A stored cross site scripting (XSS) vulnerability in index.php/legend/6.html of UK CMS v1.1.10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Comments section. |
Reflected cross-site scripting (XSS) was possible on the login page in Acronis Cyber Protect 15 prior to build 27009. |
A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arbitrary web scripts or HTML via the 'wd' parameter. |
1Securimage Wp Fixed Project 1Securimage Wp Fixed Jun 17, 2026 Aug 11, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Securimage-WP-Fixed WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/securimage-wp.php file which allows attackers to inject arbitrary web scripts, in v...Show more |
1Netgear 15D7800 Firmware R7800 FirmwareR8900 Firmware+12 moreJun 17, 2026 Aug 11, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 before 1.0.4.26, R9000 before 1.0.4.26, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3...Show more |