← Back
CWE-79

47,859 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,859)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mozilla
1Firefox
Jun 17, 2026
Jun 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTML injection is still possible. *Note: This issue only affected Firefox...Show more
Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTML injection is still possible. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 88.Show less
1Johnsoncontrols
1Exacqvision Web Service
Jun 17, 2026
Jun 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.
1Johnsoncontrols
1Exacqvision Enterprise Manager
Jun 17, 2026
Jun 24, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.
1Avaya
1Aura Experience Portal
Jun 17, 2026
Jun 24, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0...Show more
Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).Show less
1Catfish Cms
1Catfish Cms
Jun 17, 2026
Jun 23, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross site scripting (XSS) vulnerability in Catfish CMS 4.9.90 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "announcement_gonggao" parameter.
1Get Simple
1Getsimplecms
Jun 17, 2026
Jun 23, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php
1Get Simple
1Getsimplecms
Jun 17, 2026
Jun 23, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.
1Get Simple
1Getsimplecms
Jun 17, 2026
Jun 23, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_sent function.
1Phpipam
1Phpipam
Jun 17, 2026
Jun 23, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.
1Get Simple
1Getsimplecms
Jun 17, 2026
Jun 23, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets.
1Get Simple
1Getsimplecms
Jun 17, 2026
Jun 23, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS 3.4.0a in admin/edit.php.
1Get Simple
1Getsimplecms
Jun 17, 2026
Jun 23, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by adding comments or jpg and other file header information to the content of xla, pages, and gzip files,
1Contao
1Contao
Jun 17, 2026
Jun 23, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the...Show more
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.Show less
1Ampache
1Ampache
Jun 17, 2026
Jun 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authenticat...Show more
Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php page unless the site is running in demo mode. This issue has been resolved in 4.4.3.Show less
1Wuzhicms
1Wuzhicms
Jun 17, 2026
Jun 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) in Wuzhi CMS v4.1.0 allows remote attackers to execute arbitrary code via the "Title" parameter in the component "/coreframe/app/guestbook/myissue.php".
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Jun 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php. Remote registered users can exploit the vulnerability to obtain user cookie dat...Show more
PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php. Remote registered users can exploit the vulnerability to obtain user cookie data.Show less
1Icehrm
1Icehrm
Jun 17, 2026
Jun 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross site scripting (XSS) vulnerability in Ice Hrm 29.0.0.OS, allows attackers to execute arbitrary code via the parameters to the /app/ endpoint.
1Icehrm
1Icehrm
Jun 17, 2026
Jun 22, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross site scripting (XSS) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to execute arbitrary web scripts or HTML via a crafted file uploaded into the Document Management tab. The expl...Show more
A stored cross site scripting (XSS) vulnerability was discovered in Ice Hrm 29.0.0.OS which allows attackers to execute arbitrary web scripts or HTML via a crafted file uploaded into the Document Management tab. The exploit is triggered when a user visits the upload location of the crafted file.Show less
1Vanillaforums
1Vanilla Forums
Nov 21, 2024
Jun 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the client side.
1Ec Cube
1Business Form Output
Jun 17, 2026
Jun 22, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in EC-CUBE Category contents plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script by leading an administrator or a user...Show more
Cross-site scripting vulnerability in EC-CUBE Category contents plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script by leading an administrator or a user to a specially crafted page and to perform a specific operation.Show less