← Back
CWE-79

47,997 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,997)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
4Data Center
JiraJira Data Center+1 more
Jun 17, 2026
Jun 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and from version 8.6.0 before version 8.13.7, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitra...Show more
The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and from version 8.6.0 before version 8.13.7, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.Show less
1Atlassian
3Data Center
JiraJira Server
Jun 17, 2026
Jun 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitr...Show more
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.Show less
1Flarum
1Flarum
Jun 17, 2026
Jun 7, 2021
N/A· v4
10.0 CRITICAL· v3
4.3 MEDIUM· v2
Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be converted into HTML DOM nodes when rendered. This change was made after v0.1.0-beta.16 (our last beta befor...Show more
Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be converted into HTML DOM nodes when rendered. This change was made after v0.1.0-beta.16 (our last beta before v1.0.0) and was not noticed or documented. This allowed for any user to type malicious HTML markup within certain user input fields and have this execute on client browsers. The example which led to the discovery of this vulnerability was in the forum search box. Entering faux-malicious HTML markup, such as <script>alert('test')</script> resulted in an alert box appearing on the forum. This attack could also be modified to perform AJAX requests on behalf of a user, possibly deleting discussions, modifying their settings or profile, or even modifying settings on the Admin panel if the attack was targetted towards a privileged user. All Flarum communities that run flarum v1.0.0 or v1.0.1 are impacted. The vulnerability has been fixed and published as flarum/core v1.0.2. All communities running Flarum v1.0 have to upgrade as soon as possible to v1.0.2.Show less
1Datasette
1Datasette
Jun 17, 2026
Jun 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Datasette is an open source multi-tool for exploring and publishing data. The `?_trace=1` debugging feature in Datasette does not correctly escape generated HTML, resulting in a [reflected cross-site scripting](https://o...Show more
Datasette is an open source multi-tool for exploring and publishing data. The `?_trace=1` debugging feature in Datasette does not correctly escape generated HTML, resulting in a [reflected cross-site scripting](https://owasp.org/www-community/attacks/xss/#reflected-xss-attacks) vulnerability. This vulnerability is particularly relevant if your Datasette installation includes authenticated features using plugins such as [datasette-auth-passwords](https://datasette.io/plugins/datasette-auth-passwords) as an attacker could use the vulnerability to access protected data. Datasette 0.57 and 0.56.1 both include patches for this issue. If you run Datasette behind a proxy you can workaround this issue by rejecting any incoming requests with `?_trace=` or `&_trace=` in their query string parameters.Show less
1Accela
1Civic Platform
Jun 17, 2026
Jun 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are configurable security flags and we are unable to reproduce them with the a...Show more
In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are configurable security flags and we are unable to reproduce them with the available information.Show less
1Easy Preloader Project
1Easy Preloader
Jun 17, 2026
Jun 7, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Easy Preloader WordPress plugin through 1.0.0 does not sanitise its setting fields, leading to authenticated (admin+) Stored Cross-Site scripting issues
1Iflychat
1Iflychat
Jun 17, 2026
Jun 7, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The iFlyChat WordPress plugin before 4.7.0 does not sanitise its APP ID setting before outputting it back in the page, leading to an authenticated Stored Cross-Site Scripting issue
1Jnews
1Jnews
Jun 17, 2026
Jun 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue.
1Pagelayer
1Pagelayer
Jun 17, 2026
Jun 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PageLayer before 1.3.5 allows reflected XSS via color settings.
1Pagelayer
1Pagelayer
Jun 17, 2026
Jun 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.
1Zohocorp
1Manageengine Key Manager Plus
Jun 17, 2026
Jun 7, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.
12sic
12sxc
Jun 17, 2026
Jun 7, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in 2sic 2sxc before 11.22. A XSS vulnerability in the sxcver parameter of dnn/ui.html allows an attacker to craft a malicious URL that executes a JavaScript payload in a victim's browser.
1Auth0
1Lock
Jun 17, 2026
Jun 4, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflected XSS. An attacker can execute arbitrary code when the library's `flashMessage` feature is utilized...Show more
auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflected XSS. An attacker can execute arbitrary code when the library's `flashMessage` feature is utilized and user input or data from URL parameters is incorporated into the `flashMessage` or the library's `languageDictionary` feature is utilized and user input or data from URL parameters is incorporated into the `languageDictionary`. The vulnerability is patched in version 11.30.1.Show less
1Chiyu Tech
3Bf 430 Firmware
Bf 431 FirmwareBf 450m Firmware
Jun 17, 2026
Jun 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of sanitization of the input on the components man.cgi, if.cgi, dhcpc.cg...Show more
Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of sanitization of the input on the components man.cgi, if.cgi, dhcpc.cgi, ppp.cgi.Show less
1Bloofox
1Bloofoxcms
Jun 17, 2026
Jun 4, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter.
1Appcms
1Appcms
Jun 17, 2026
Jun 3, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker to obtain sensitive information of other users.
1Zzcms
1Zzcms
Jun 17, 2026
Jun 3, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via /user/manage.php.
1Yzmcms
1Yzmcms
Jun 17, 2026
Jun 3, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicious XSS on the /admin/system_manage/user_config_edit.html page.
1Pbootcms
1Pbootcms
Jun 17, 2026
Jun 3, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php.
1Mcafee
1Database Security
Jun 17, 2026
Jun 3, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to embed JavaScript code when configuring the...Show more
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to embed JavaScript code when configuring the name of a database to be monitored. This would be triggered when any authorized user logs into the DBSec interface and opens the properties configuration page for this database.Show less