CWE-79
47,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross Site Scripting (XSS) vulnerability exists in bycms v3.0.4 via the title parameter in the edit function in Document.php. |
Cross Site Scripting (XSS) vulnerability exists in DamiCMS v6.0.6 via the title parameter in the doadd function in LabelAction.class.php. |
Cross Site Scripting (XSS) vulnerability exists in UKCMS v1.1.10 via data in the index function in Single.php |
3Ckeditor FedoraprojectOracle10Application Express Banking Party ManagementCkeditor+7 moreJun 17, 2026 Aug 12, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allo...Show more |
3Ckeditor FedoraprojectOracle13Application Express Banking Party ManagementCkeditor+10 moreJun 17, 2026 Aug 12, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse un...Show more |
Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php. |
Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php. |
Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7. |
A stored cross site scripting (XSS) vulnerability in index.php/legend/6.html of UK CMS v1.1.10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Comments section. |
Reflected cross-site scripting (XSS) was possible on the login page in Acronis Cyber Protect 15 prior to build 27009. |
A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arbitrary web scripts or HTML via the 'wd' parameter. |
1Securimage Wp Fixed Project 1Securimage Wp Fixed Jun 17, 2026 Aug 11, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Securimage-WP-Fixed WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/securimage-wp.php file which allows attackers to inject arbitrary web scripts, in v...Show more |
1Netgear 15D7800 Firmware R7800 FirmwareR8900 Firmware+12 moreJun 17, 2026 Aug 11, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Certain NETGEAR devices are affected by stored XSS. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 before 1.0.4.26, R9000 before 1.0.4.26, RAX120 before 1.0.0.78, RBK20 before 2.3.5.26, RBR20 before 2.3...Show more |
1Netgear 18Ac2100 Firmware Ac2400 FirmwareAc2600 Firmware+15 moreJun 17, 2026 Aug 11, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.66, R6260 before 1.1.0.78, R6700v2 before 1...Show more |
1Netgear 19Ac2100 Firmware Ac2400 FirmwareAc2600 Firmware+16 moreJun 17, 2026 Aug 11, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.66, R6260 before 1.1.0.78, R6700v2 before 1...Show more |
1Netgear 19Ac2100 Firmware Ac2400 FirmwareAc2600 Firmware+16 moreJun 17, 2026 Aug 11, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Certain NETGEAR devices are affected by stored XSS. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6120 before 1.0.0.76, R6260 before 1.1.0.78, R6700v2 before 1...Show more |
1Netgear 43D3600 Firmware D6000 FirmwareD6100 Firmware+40 moreJun 17, 2026 Aug 11, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Certain NETGEAR devices are affected by stored XSS. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6100 before 1.0.0.60, D6200 before 1.1.00.36, D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000 before 1.0...Show more |
NETGEAR RAX40 devices before 1.0.3.64 are affected by stored XSS. |
A stored cross site scripting (XSS) vulnerability in the web_attr_2 field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML. |
A stored cross site scripting (XSS) vulnerability in the web_copyright field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML. |