← Back
CWE-79

47,819 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,819)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Leaflet Map Project
1Leaflet Map
Jun 17, 2026
Aug 9, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in admin update the settings via a Cross-Site Request Forgery attack. This co...Show more
The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in admin update the settings via a Cross-Site Request Forgery attack. This could lead to Cross-Site Scripting issues by either changing the URL of the JavaScript library being used, or using malicious attributions which will be executed in all page with an embed map from the pluginShow less
1Tagdiv
1Newsmag
Jun 17, 2026
Aug 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.
1Ammonia Project
1Ammonia
Jun 17, 2026
Aug 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HTML, SVG, and MathML are mishandled, a similar issue to CVE-2020-26870.
1Comrak Project
1Comrak
Jun 17, 2026
Aug 8, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in the comrak crate before 0.10.1 for Rust. It mishandles & characters, leading to XSS via &# HTML entities.
1Popojicms
1Popojicms
Jun 17, 2026
Aug 6, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A stored cross site scripting (XSS) vulnerability in /admin.php?mod=user&act=addnew of PopojiCMS 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the E-Mail field.
1Get Simple
1Getsimplecms
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets module.
1Leostream
1Connection Broker
Jun 17, 2026
Aug 6, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
LeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
1Mineweb
1Minewebcms
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious code into the 'Title' field of the component '/admin/news'.
1Naviwebs
1Navigate Cms
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\backups.php, 2) blocks\blocks.php, 3) brands\brands.php, 4) comments\comments.php, 5) coupons\coupons...Show more
Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\backups.php, 2) blocks\blocks.php, 3) brands\brands.php, 4) comments\comments.php, 5) coupons\coupons.php, 6) feeds\feeds.php, 7) functions\functions.php, 8) items\items.php, 9) menus\menus.php, 10) orders\orders.php, 11) payment_methods\payment_methods.php, 12) products\products.php, 13) profiles\profiles.php, 14) shipping_methods\shipping_methods.php, 15) templates\templates.php, 16) users\users.php, 17) webdictionary\webdictionary.php, 18) websites\websites.php, and 19) webusers\webusers.php because the initial_url function is built in these files.Show less
1Jetbrains
1Youtrack
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.
1Jetbrains
1Teamcity
Jun 17, 2026
Aug 6, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In JetBrains TeamCity before 2020.2.3, XSS was possible.
1Intelliants
1Subrion
Jun 17, 2026
Aug 6, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.
1Chikitsa
1Patient Management System
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS.
1Chikitsa
1Patient Management System
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS.
1Chikitsa
1Patient Management System
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS.
1Fortinet
2Fortianalyzer
Fortimanager
Jun 17, 2026
Aug 6, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions 7.0.0, 6.4.5 and below, 6.2.7 and below user interface, may allow a remote authenticated attacker t...Show more
Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions 7.0.0, 6.4.5 and below, 6.2.7 and below user interface, may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious payload in GET parameters.Show less
1Intelliants
1Subrion Cms
Jun 17, 2026
Aug 5, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file.
1W3eden
1Download Manager
Jun 17, 2026
Aug 5, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS att...Show more
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded JavaScript with an image extension This issue affects: WordPress Download Manager version 3.1.24 and prior versions.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Aug 5, 2021
N/A· v4
6.4 MEDIUM· v3
3.5 LOW· v2
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially craf...Show more
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files on the server.Show less
1Tecnick
1Tcexam
Jun 17, 2026
Aug 5, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile.php were not properly validated and could cause reflected XSS via the...Show more
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir parameters in tce_select_mediafile.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supplied. An attacker could craft a malicious link which, if triggered by an administrator, could result in the attacker hijacking the victim's session or performing actions on their behalf.Show less