← Back
CWE-79

47,819 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,819)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Misp
Misp Project
2Misp
Misp
Jun 22, 2026
Jul 30, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster relationships.
1Objectplanet
1Opinio
Jun 17, 2026
Jul 30, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if input to survey/admin/*.do is accepted from untrusted users.)
1Telegram
1Web K Alpha
Jun 17, 2026
Jul 30, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Telegram Web K Alpha 0.6.1 allows XSS via a document name.
1Engineercms Project
1Engineercms
Jun 17, 2026
Jul 30, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
engineercms 1.03 is vulnerable to Cross Site Scripting (XSS). There is no escaping in the nickname field on the user list page. When viewing this page, the JavaScript code will be executed in the user's browser.
1Nagios
1Log Server
Jun 17, 2026
Jul 30, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp parameter. This affects users who open a crafted link or third-party web p...Show more
Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp parameter. This affects users who open a crafted link or third-party web page.Show less
1Nagios
1Log Server
Jun 17, 2026
Jul 30, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-...Show more
Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page.Show less
1Groupsession
3Groupsession
Groupsession BycloudGroupsession Zion
Jun 17, 2026
Jul 30, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION fro...Show more
Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote attacker to inject an arbitrary script by sending a specially crafted request to a specific URL.Show less
1Groupsession
3Groupsession
Groupsession BycloudGroupsession Zion
Jun 17, 2026
Jul 30, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION fro...Show more
Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote attacker to inject an arbitrary script by sending a specially crafted request to a specific URL.Show less
1Tecnick
1Tcexam
Jun 17, 2026
Jul 30, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining with a period will be rendered as text/html. An attacker with access to...Show more
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_select_mediafile.php could upload a malicious javascript payload which would be triggered when another user views the file.Show less
1Tecnick
1Tcexam
Jun 17, 2026
Jul 30, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_f...Show more
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_filemanager.php could upload a malicious javascript payload which would be triggered when another user views the file.Show less
1Nukeviet
1Nukeviet
Jun 17, 2026
Jul 30, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.
1Tidesec
1Wdscanner
Jun 17, 2026
Jul 30, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting vulnerabiity exists in WDScanner 1.1 in the system management page.
1S Cms
1S Cms
Jun 17, 2026
Jul 30, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored cross site scripting (XSS) vulnerability in /app/config/of S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
1S Cms
1S Cms
Jun 17, 2026
Jul 30, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored cross site scripting (XSS) vulnerability in /app/form_add/of S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Title Entry text box.
1S Cms
1S Cms
Jun 17, 2026
Jul 30, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross site scripting (XSS) vulnerability in S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Copyright text box under Basic Settings.
1Yzmcms
1Yzmcms
Jun 17, 2026
Jul 30, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerabiity in YzmCMS 5.2 via the site_code parameter in admin/index/init.html.
1Hucart
1Hucart
Jun 17, 2026
Jul 30, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability in HuCart 5.7.4 via nickname in index.php.
1Egain
1Chat
Jun 17, 2026
Jul 30, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
eGain Chat 15.5.5 allows XSS via the Name (aka full_name) field.
1Sophos
1Unified Threat Management
Jun 17, 2026
Jul 29, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.
1Curly Bracket Parser Project
1Curly Bracket Parser
Jun 17, 2026
Jul 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
This affects all versions of package curly-bracket-parser. When used as a template library, it does not properly sanitize the user input.