CWE-79
47,819 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,819)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Leaflet Map Project 1Leaflet Map Jun 17, 2026 Aug 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in admin update the settings via a Cross-Site Request Forgery attack. This co...Show more |
The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability. |
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870. |
An issue was discovered in the comrak crate before 0.10.1 for Rust. It mishandles & characters, leading to XSS via &# HTML entities. |
A stored cross site scripting (XSS) vulnerability in /admin.php?mod=user&act=addnew of PopojiCMS 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the E-Mail field. |
A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets module. |
1Leostream 1Connection Broker Jun 17, 2026 Aug 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 LeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer |
Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious code into the 'Title' field of the component '/admin/news'. |
Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\backups.php, 2) blocks\blocks.php, 3) brands\brands.php, 4) comments\comments.php, 5) coupons\coupons...Show more |
In JetBrains YouTrack before 2021.2.17925, stored XSS was possible. |
In JetBrains TeamCity before 2020.2.3, XSS was possible. |
Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page. |
1Chikitsa 1Patient Management System Jun 17, 2026 Aug 6, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS. |
1Chikitsa 1Patient Management System Jun 17, 2026 Aug 6, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS. |
1Chikitsa 1Patient Management System Jun 17, 2026 Aug 6, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS. |
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Aug 6, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions 7.0.0, 6.4.5 and below, 6.2.7 and below user interface, may allow a remote authenticated attacker t...Show more |
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file. |
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS att...Show more |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially craf...Show more |
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile.php were not properly validated and could cause reflected XSS via the...Show more |