← Back
CWE-79

47,752 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,752)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mineweb
1Minewebcms
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious code into the 'Title' field of the component '/admin/news'.
1Naviwebs
1Navigate Cms
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\backups.php, 2) blocks\blocks.php, 3) brands\brands.php, 4) comments\comments.php, 5) coupons\coupons...Show more
Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\backups.php, 2) blocks\blocks.php, 3) brands\brands.php, 4) comments\comments.php, 5) coupons\coupons.php, 6) feeds\feeds.php, 7) functions\functions.php, 8) items\items.php, 9) menus\menus.php, 10) orders\orders.php, 11) payment_methods\payment_methods.php, 12) products\products.php, 13) profiles\profiles.php, 14) shipping_methods\shipping_methods.php, 15) templates\templates.php, 16) users\users.php, 17) webdictionary\webdictionary.php, 18) websites\websites.php, and 19) webusers\webusers.php because the initial_url function is built in these files.Show less
1Jetbrains
1Youtrack
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 6, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains TeamCity before 2020.2.3, XSS was possible.
1Intelliants
1Subrion
Jun 17, 2026
Aug 6, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.
1Chikitsa
1Patient Management System
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS.
1Chikitsa
1Patient Management System
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS.
1Chikitsa
1Patient Management System
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS.
1Fortinet
2Fortianalyzer
Fortimanager
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions 7.0.0, 6.4.5 and below, 6.2.7 and below user interface, may allow a remote authenticated attacker t...Show more
Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions 7.0.0, 6.4.5 and below, 6.2.7 and below user interface, may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious payload in GET parameters.Show less
1Intelliants
1Subrion Cms
Jun 17, 2026
Aug 5, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file.
1W3eden
1Download Manager
Jun 17, 2026
Aug 5, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS att...Show more
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded JavaScript with an image extension This issue affects: WordPress Download Manager version 3.1.24 and prior versions.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Aug 5, 2021
N/A· v4
6.4 MEDIUM· v3
3.5 LOW· v2
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially craf...Show more
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files on the server.Show less
1Tecnick
1Tcexam
Jun 17, 2026
Aug 5, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile.php were not properly validated and could cause reflected XSS via the...Show more
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supplied. An attacker could craft a malicious link which, if triggered by an administrator, could result in the attacker hijacking the victim's session or performing actions on their behalf.Show less
1Tecnick
1Tcexam
Jun 17, 2026
Aug 5, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php were not properly validated and could cause reflected XSS via the unsan...Show more
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supplied. An attacker could craft a malicious link which, if triggered by an administrator, could result in the attacker hijacking the victim's session or performing actions on their behalf.Show less
1Mattermost
1Mattermost
Jun 17, 2026
Aug 5, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost.
1Gitlab
1Gitlab
Jun 17, 2026
Aug 5, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default branch name.
1Zte
1Zxiptv Firmware
Jun 17, 2026
Aug 5, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ZTE's big video business platform has two reflective cross-site scripting (XSS) vulnerabilities. Due to insufficient input verification, the attacker could implement XSS attacks by tampering with the parameters, to affec...Show more
ZTE's big video business platform has two reflective cross-site scripting (XSS) vulnerabilities. Due to insufficient input verification, the attacker could implement XSS attacks by tampering with the parameters, to affect the operations of valid users. This affects: <ZXIPTV><ZXIPTV-EAS_PV5.06.04.09>Show less
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Aug 5, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker..
1Onenav
1Onenav
Jun 17, 2026
Aug 5, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not any XSS protection at present, because the attack risk is largely limited to a compromised account; h...Show more
OneNav beta 0.9.12 allows XSS via the Add Link feature. NOTE: the vendor's position is that there intentionally is not any XSS protection at present, because the attack risk is largely limited to a compromised account; however, XSS protection is planned for a future release.Show less
1Espocrm
1Espocrm
Jun 17, 2026
Aug 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 6.1.7 of the product.