← Back
CWE-79

47,859 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,859)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Php Fusion
1Php Fusion
Jun 17, 2026
Jul 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross site scripting (XSS) vulnerability in administration/settings_main.php of PHP-Fusion 9.03.50 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "...Show more
A stored cross site scripting (XSS) vulnerability in administration/settings_main.php of PHP-Fusion 9.03.50 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Site footer" field.Show less
1Getkirby
1Kirby
Jun 17, 2026
Jul 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in the pages and files section for example) displayed HTML in page titles as it is. This could be used f...Show more
Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in the pages and files section for example) displayed HTML in page titles as it is. This could be used for cross-site scripting (XSS) attacks. Malicious authenticated Panel users can escalate their privileges if they get access to the Panel session of an admin user. Visitors without Panel access can use the attack vector if the site allows changing site data from a frontend form. Kirby 3.5.7 patches the vulnerability. As a partial workaround, site administrators can protect against attacks from visitors without Panel access by validating or sanitizing provided data from the frontend form.Show less
1Mediawiki
1Mediawiki
Jun 17, 2026
Jul 2, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in the SportsTeams extension in MediaWiki through 1.36. Within several special pages, a privileged user could inject arbitrary HTML and JavaScript within various data fields. The attack could...Show more
An XSS issue was discovered in the SportsTeams extension in MediaWiki through 1.36. Within several special pages, a privileged user could inject arbitrary HTML and JavaScript within various data fields. The attack could easily propagate across many pages for many users.Show less
1Mediawiki
1Mediawiki
Jun 17, 2026
Jul 2, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An XSS issue was discovered in the SocialProfile extension in MediaWiki through 1.36. Within several gift-related special pages, a privileged user with the awardmanage right could inject arbitrary HTML and JavaScript wit...Show more
An XSS issue was discovered in the SocialProfile extension in MediaWiki through 1.36. Within several gift-related special pages, a privileged user with the awardmanage right could inject arbitrary HTML and JavaScript within various gift-related data fields. The attack could easily propagate across many pages for many users.Show less
1Phplist
1Phplist
Jun 17, 2026
Jul 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add a list" field under the "Import Emails" module.
1Phplist
1Phplist
Jun 17, 2026
Jul 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Configure categories" field under the "Categorise Lists...Show more
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Configure categories" field under the "Categorise Lists" module.Show less
1Phplist
1Phplist
Jun 17, 2026
Jul 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "List Description" field under the "Edit A List" module.
1Phplist
1Phplist
Jun 17, 2026
Jul 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Send test" field under the "Start or continue campaign"...Show more
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Send test" field under the "Start or continue campaign" module.Show less
1Phplist
1Phplist
Jun 17, 2026
Jul 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Edit Values" field under the "Configure Attributes" mod...Show more
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Edit Values" field under the "Configure Attributes" module.Show less
1Monstra
1Monstra Cms
Jun 17, 2026
Jul 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross site scripting (XSS) vulnerability in Monstra CMS version 3.0.4 allows attackers to execute arbitrary web scripts or HTML via crafted a payload entered into the "Site Name" field under the "Site Settings"...Show more
A stored cross site scripting (XSS) vulnerability in Monstra CMS version 3.0.4 allows attackers to execute arbitrary web scripts or HTML via crafted a payload entered into the "Site Name" field under the "Site Settings" module.Show less
1Ibm
1Datacap Navigator
Jun 17, 2026
Jul 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Datacap Fastdoc Capture (IBM Datacap Navigator 9.1.7 ) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality...Show more
IBM Datacap Fastdoc Capture (IBM Datacap Navigator 9.1.7 ) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 191753.Show less
1Phpgurukul
1Teachers Record Management System
Jun 17, 2026
Jul 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated users to inject arbitrary web script or HTML via the 'email' POST parameter in adminprofile.php.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Jul 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.
1Ikalka Rss Reader Project
1Ikalka Rss Reader
Jun 17, 2026
Jul 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in IkaIka RSS Reader all versions allows a remote attacker to inject an arbitrary script via unspecified vectors.
1Qnap
1Q'center
Jun 17, 2026
Jul 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
This issue affects: QNAP Systems Inc. Q'center versions prior to 1.11.1004.
1Qnap
1Qulog Center
Jun 17, 2026
Jul 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A stored XSS vulnerability has been reported to affect QNAP NAS running QuLog Center. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QuLog Center version...Show more
A stored XSS vulnerability has been reported to affect QNAP NAS running QuLog Center. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QuLog Center versions prior to 1.2.0.Show less
1Qnap
2Qts
Quts Hero
Jun 17, 2026
Jul 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to...Show more
An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.2.1566 Build 20210202. QNAP Systems Inc. QuTS hero versions prior to h4.5.2.1638 build 20210414. This issue does not affect: QNAP Systems Inc. QTS 4.5.3.Show less
1Akcp
5Sensorprobe2 Firmware
Sensorprobe4 FirmwareSensorprobe8 X20 Firmware+2 more
Jun 17, 2026
Jun 30, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introduce arbitrary JavaScript via the Sensor Description, Email (from/to/cc...Show more
Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introduce arbitrary JavaScript via the Sensor Description, Email (from/to/cc), System Name, and System Location fields.Show less
1Craftcms
1Craft Cms
Jun 17, 2026
Jun 30, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.
1Chevereto
1Chevereto
Jul 9, 2026
Jun 30, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage.