CWE-79
47,997 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (47,997)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Atlassian 4Data Center JiraJira Data Center+1 moreJun 17, 2026 Jun 7, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and from version 8.6.0 before version 8.13.7, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitra...Show more |
1Atlassian 3Data Center JiraJira ServerJun 17, 2026 Jun 7, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitr...Show more |
Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be converted into HTML DOM nodes when rendered. This change was made after v0.1.0-beta.16 (our last beta befor...Show more |
Datasette is an open source multi-tool for exploring and publishing data. The `?_trace=1` debugging feature in Datasette does not correctly escape generated HTML, resulting in a [reflected cross-site scripting](https://o...Show more |
In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are configurable security flags and we are unable to reproduce them with the a...Show more |
1Easy Preloader Project 1Easy Preloader Jun 17, 2026 Jun 7, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The Easy Preloader WordPress plugin through 1.0.0 does not sanitise its setting fields, leading to authenticated (admin+) Stored Cross-Site scripting issues |
The iFlyChat WordPress plugin before 4.7.0 does not sanitise its APP ID setting before outputting it back in the page, leading to an authenticated Stored Cross-Site Scripting issue |
The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue. |
PageLayer before 1.3.5 allows reflected XSS via color settings. |
PageLayer before 1.3.5 allows reflected XSS via the font-size parameter. |
1Zohocorp 1Manageengine Key Manager Plus Jun 17, 2026 Jun 7, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD. |
An issue was discovered in 2sic 2sxc before 11.22. A XSS vulnerability in the sxcver parameter of dnn/ui.html allows an attacker to craft a malicious URL that executes a JavaScript payload in a victim's browser. |
auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflected XSS. An attacker can execute arbitrary code when the library's `flashMessage` feature is utilized...Show more |
1Chiyu Tech 3Bf 430 Firmware Bf 431 FirmwareBf 450m FirmwareJun 17, 2026 Jun 4, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of sanitization of the input on the components man.cgi, if.cgi, dhcpc.cg...Show more |
BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter. |
AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker to obtain sensitive information of other users. |
An issue was discovered in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via /user/manage.php. |
A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicious XSS on the /admin/system_manage/user_config_edit.html page. |
Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php. |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to embed JavaScript code when configuring the...Show more |