CWE-79
47,859 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,859)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross Site Scripting (XSS) vulnerability in umeditor v1.2.3 via /public/common/umeditor/php/getcontent.php. |
1Wayang Cms Project 1Wayang Cms Jun 17, 2026 Jul 14, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross site scripting (XSS) vulnerability in index.php of Wayang-CMS v1.0 allows attackers to execute arbitrary web scripts or HTML via a constructed payload created by adding the X-Forwarded-For field to the header. |
Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 via the (1) "About Yourself” section under the “My Profile” page, " (2) “Hotel Policy” field under the “Hotel Details”...Show more |
A Cross-site scripting (XSS) vulnerability in the "View in Browser" feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SVG image. |
SAP Lumira Server version 2.4 does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This would allow an attacker with basic level privileges to store a malicious scri...Show more |
LINE client for iOS before 10.16.3 allows cross site script with specific header in WebView. |
1Ibm 1Cloud Pak For Applications Jun 17, 2026 Jul 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more |
1Ibm 1Cloud Pak For Applications Jun 17, 2026 Jul 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more |
1Ibm 1Cloud Pak For Applications Jun 17, 2026 Jul 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more |
1Ibm 1Cloud Pak For Applications Jun 17, 2026 Jul 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more |
1Ibm 1Cloud Pak For Applications Jun 17, 2026 Jul 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more |
1Ibm 1Cloud Pak For Applications Jun 17, 2026 Jul 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more |
1Ibm 1Cloud Pak For Applications Jun 17, 2026 Jul 13, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Cloud Pak for Applications 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more |
1Siemens 1Teamcenter Active Workspace Jun 17, 2026 Jul 13, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in Teamcenter Active Workspace V4 (All versions < V4.3.9), Teamcenter Active Workspace V5.0 (All versions < V5.0.7), Teamcenter Active Workspace V5.1 (All versions < V5.1.4). A reflect...Show more |
1Eventespresso 1Event Espresso Jun 17, 2026 Jul 13, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability in wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/ee_msg_admin_overview.template.php in the Event Espresso Core plugin before 4.10.7.p for WordPress a...Show more |
1Nextcloud 1Nextcloud Server Jun 17, 2026 Jul 12, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Nextcloud Text is a collaborative document editing application that uses Markdown. A cross-site scripting vulnerability is present in versions prior to 19.0.13, 20.0.11, and 21.0.3. The Nextcloud Text application shipped...Show more |
In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting issu...Show more |
The Sign-up Sheets WordPress plugin before 1.0.14 did not sanitise or escape some of its fields when creating a new sheet, allowing high privilege users to add JavaScript in them, leading to a Stored Cross-Site Scripting...Show more |
1Prothemedesign 1Browser Screenshots Jun 17, 2026 Jul 12, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Browser Screenshots WordPress plugin before 1.7.6 allowed authenticated users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks as the image_class parameter of the browser-shot shortcod...Show more |
The Glass WordPress plugin through 1.3.2 does not sanitise or escape its "Glass Pages" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin did not have CSRF check...Show more |