CWE-79
47,859 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,859)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Expresstech 1Quiz And Survey Master Jun 17, 2026 Jun 20, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-...Show more |
1Striptags Project 1Striptags Jun 17, 2026 Jun 18, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The npm package "striptags" is an implementation of PHP's strip_tags in Typescript. In striptags before version 3.2.0, a type-confusion vulnerability can cause `striptags` to concatenate unsanitized strings when an array...Show more |
CheckSec Canopy before 3.5.2 allows XSS attacks against the login page via the LOGIN_PAGE_DISCLAIMER parameter. |
No filtering of cross-site scripting (XSS) payloads in the markdown-editor in Zettlr 1.8.7 allows attackers to perform remote code execution via a crafted file. |
A cross-site scripting (XSS) vulnerability exists in Znote 0.5.2. An attacker can insert payloads, and the code execution will happen immediately on markdown view mode. |
An issue was discovered in JPress v3.3.0 and below. There are XSS vulnerabilities in the template module and tag management module. If you log in to the background by means of weak password, the storage XSS vulnerability...Show more |
The login page in the MCUsystem does not filter with special characters, which allows remote attackers can inject JavaScript without privilege and thus perform reflected XSS attacks. |
1Trendnet 1Tw100 S4w1ca Firmware Jun 17, 2026 Jun 17, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In TrendNet TW100-S4W1CA 2.3.32, it is possible to inject arbitrary JavaScript into the router's web interface via the "echo" command. |
An XSS issue was discovered in manage_custom_field_edit_page.php in MantisBT before 2.25.2. Unescaped output of the return parameter allows an attacker to inject code into a hidden input field. |
Wagtail is an open source content management system built on Django. A cross-site scripting vulnerability exists in versions 2.13-2.13.1, versions 2.12-2.12.4, and versions prior to 2.11.8. When the `{% include_block %}`...Show more |
In Fiyo CMS 2.0.6.1, the 'tag' parameter results in an unauthenticated XSS attack. |
An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Title of Login Page" text box or "TITLE" parameter in IPFire 2.21 (x86_64) - Core Update 130. It allows an authentica...Show more |
1Trendmicro 1Interscan Web Security Virtual Appliance Jun 17, 2026 Jun 17, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Trend Micro InterScan Web Security Virtual Appliance version 6.5 was found to have a reflected cross-site scripting (XSS) vulnerability in the product's Captive Portal. |
In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS. These SVG files can contain malicious scripts. This file will be uploaded to the system and it will not be stripped or filtered. The...Show more |
Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field. |
1Cisco 9Sf220 24 Firmware Sf220 24p FirmwareSf220 48 Firmware+6 moreJun 17, 2026 Jun 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root use...Show more |
1Cisco 9Sf220 24 Firmware Sf220 24p FirmwareSf220 48 Firmware+6 moreJun 17, 2026 Jun 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root use...Show more |
1Cisco 4Packaged Contact Center Enterprise Unified Contact Center EnterpriseUnified Contact Center Express+1 moreJun 17, 2026 Jun 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. T...Show more |
bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code. |
Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission. |