← Back
CWE-79

47,997 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,997)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
1Oneview For Vmware Vcenter
Jun 17, 2026
Jun 3, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be exploited remotely to allow Cross-Site Scripting. HPE has released the following software update to resolve the vulnerability in HPE OneView for...Show more
A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be exploited remotely to allow Cross-Site Scripting. HPE has released the following software update to resolve the vulnerability in HPE OneView for VMware vCenter (OV4VC).Show less
1Qnap
1Q'center
Jun 17, 2026
Jun 3, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already fixed this vul...Show more
A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already fixed this vulnerability in the following versions of Q’center: QTS 4.5.3: Q’center v1.12.1012 and later QTS 4.3.6: Q’center v1.10.1004 and later QTS 4.3.3: Q’center v1.10.1004 and later QuTS hero h4.5.2: Q’center v1.12.1012 and later QuTScloud c4.5.4: Q’center v1.12.1012 and laterShow less
1Qnap
3Qts
Quts HeroQutscloud
Jun 17, 2026
Jun 3, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A DOM-based XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions...Show more
A DOM-based XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.3.1652 Build 20210428. QNAP Systems Inc. QuTS hero versions prior to h4.5.2.1638 Build 20210414. QNAP Systems Inc. QuTScloud versions prior to c4.5.5.1656 Build 20210503. This issue does not affect: QNAP Systems Inc. QTS 4.3.6; 4.3.3.Show less
1Ibm
9Collaborative Lifecycle Management
Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 more
Jun 17, 2026
Jun 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential...Show more
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199408.Show less
1Ibm
9Collaborative Lifecycle Management
Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 more
Jun 17, 2026
Jun 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential...Show more
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199406.Show less
1Ibm
9Collaborative Lifecycle Management
Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 more
Jun 17, 2026
Jun 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential...Show more
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194449.Show less
1Ibm
9Collaborative Lifecycle Management
Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 more
Jun 17, 2026
Jun 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potential...Show more
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193737.Show less
1Ibm
9Collaborative Lifecycle Management
Engineering Lifecycle ManagementEngineering Lifecycle Optimization Engineering Insights+6 more
Jun 17, 2026
Jun 2, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality...Show more
IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192470.Show less
1Redhat
2Noobaa Operator
Openshift Container Platform
Jun 17, 2026
Jun 2, 2021
N/A· v4
7.1 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The inp...Show more
A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being injected into an application's response. The highest threat to the system is for confidentiality, availability, and integrity.Show less
1Mozilla
1Firefox
Nov 21, 2024
Jun 2, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and con...Show more
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.Show less
1Chiyu Tech
11Bf 630 Firmware
Bf 631 FirmwareBiosense Firmware+8 more
Jun 17, 2026
Jun 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.
1Chiyu Tech
15Bf 430 Firmware
Bf 431 FirmwareBf 450m Firmware+12 more
Jun 17, 2026
Jun 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC due to a lack of sanitization when the...Show more
An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC due to a lack of sanitization when the HTTP 404 message is generated.Show less
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Jun 1, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability was discovered in the Administrator panel on the 'Setting News' module on CMS Made Simple 2.2.14 which allows an attacker to execute arbitrary web scripts.
1Pfsense
1Pfsense
Jun 17, 2026
Jun 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attacker to execute arbitrary web scripts via exploitation of the load_balancer_monitor.php function.
1Bigtreecms
1Bigtree Cms
Jun 17, 2026
Jun 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability was discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary web scripts or HTML via the page content to site/index.php/ad...Show more
A stored cross-site scripting (XSS) vulnerability was discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary web scripts or HTML via the page content to site/index.php/admin/pages/update.Show less
1Smartdatasoft
1Car Repair Services & Auto Mechanic
Jun 17, 2026
Jun 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey search parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issu...Show more
The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey search parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issueShow less
1Connekthq
1Instant Images One Click Unsplash Uploads
Jun 17, 2026
Jun 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/upload.php?page=instant...Show more
The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/upload.php?page=instant-images), only validating them client side before saving them, leading to a Stored Cross-Site Scripting issue.Show less
1Content Copy Protection & Prevent Image Save Project
1Content Copy Protection & Prevent Image Save
Jun 17, 2026
Jun 1, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its settings, not perform any validation and sanitisation on them, allowing attackers to make a logged in...Show more
The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its settings, not perform any validation and sanitisation on them, allowing attackers to make a logged in administrator set arbitrary XSS payloads in them.Show less
1Smooth Scroll Page Up/down Buttons Project
1Smooth Scroll Page Up/down Buttons
Jun 17, 2026
Jun 1, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client side. This could allow...Show more
The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client side. This could allow high privilege users (such as admin) to set XSS payloads in themShow less
1Cartflows
1Cartflows
Jun 17, 2026
Jun 1, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sanitise its facebook_pixel_id and google_analytics_id settings, allowing high privilege users to set XSS...Show more
The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sanitise its facebook_pixel_id and google_analytics_id settings, allowing high privilege users to set XSS payload in them, which will either be executed on pages generated by the plugin, or the whole website depending on the settings used.Show less