← Back
CWE-79

48,004 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (48,004)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Plone
1Plone
Jun 17, 2026
May 21, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document.
1Plone
1Plone
Jun 17, 2026
May 21, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Plone through 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content item.
2Plone
Zope
2Plone
Zope
Jun 17, 2026
May 21, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and other products, allow Reflected XSS.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
May 20, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field.
1Halo
1Halo
Jun 17, 2026
May 20, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability in Halo 1.1.3 via post publish components in the manage panel, which lets a remote malicious user execute arbitrary code.
1Plone
1Plone
Jun 17, 2026
May 20, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Plone CMS until version 5.2.4 has a stored Cross-Site Scripting (XSS) vulnerability in the user fullname property and the file upload functionality. The user's input data is not properly encoded when being echoed back to...Show more
Plone CMS until version 5.2.4 has a stored Cross-Site Scripting (XSS) vulnerability in the user fullname property and the file upload functionality. The user's input data is not properly encoded when being echoed back to the user. This data can be interpreted as executable code by the browser and allows an attacker to execute JavaScript in the context of the victim's browser if the victim opens a vulnerable page containing an XSS payload.Show less
1Fusionpbx
1Fusionpbx
Jun 17, 2026
May 20, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "f" variable in app\vars\vars_textarea.php.
1Opennms
2Horizon
Meridian
Jun 17, 2026
May 20, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian...Show more
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site Scripting, since the function `validateFormInput()` performs improper validation checks on the input sent to the `groupName` and `groupComment` parameters. Due to this flaw, an authenticated attacker could inject arbitrary script and trick other admin users into downloading malicious files which can cause severe damage to the organization using opennms.Show less
1Opennms
2Horizon
Meridian
Jun 17, 2026
May 20, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian...Show more
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site Scripting since there is no validation on the input being sent to the `name` parameter in `noticeWizard` endpoint. Due to this flaw an authenticated attacker could inject arbitrary script and trick other admin users into downloading malicious files.Show less
1Fusionpbx
1Fusionpbx
Jun 17, 2026
May 20, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scriptiong (XSS) vulnerability exists in FusionPBX 4.5.7 allows remote malicious users to inject arbitrary web script or HTML via an unsanitized "query_string" variable in app\devices\device_imports.php.
1Redhat
9Build Of Quarkus
Data GridDescision Manager+6 more
Jun 17, 2026
May 20, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality...Show more
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.Show less
1Emerson
4X Stream Enhanced Xefd Firmware
X Stream Enhanced Xegk FirmwareX Stream Enhanced Xegp Firmware+1 more
Jun 17, 2026
May 20, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications do not validate webpage input, which could allow an attacker to inject arbitrary HTML code into a...Show more
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications do not validate webpage input, which could allow an attacker to inject arbitrary HTML code into a webpage. This would allow an attacker to modify the page and display incorrect or undesirable data.Show less
1Adminer
1Adminer
Jun 17, 2026
May 19, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP...Show more
Adminer is open-source database management software. A cross-site scripting vulnerability in Adminer versions 4.6.1 to 4.8.0 affects users of MySQL, MariaDB, PgSQL and SQLite. XSS is in most cases prevented by strict CSP in all modern browsers. The only exception is when Adminer is using a `pdo_` extension to communicate with the database (it is used if the native extensions are not enabled). In browsers without CSP, Adminer versions 4.6.1 to 4.8.0 are affected. The vulnerability is patched in version 4.8.1. As workarounds, one can use a browser supporting strict CSP or enable the native PHP extensions (e.g. `mysqli`) or disable displaying PHP errors (`display_errors`).Show less
1Hedgedoc
1Hedgedoc
Jun 17, 2026
May 19, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
HedgeDoc is a platform to write and share markdown. HedgeDoc before version 1.8.2 is vulnerable to a cross-site scripting attack using the YAML-metadata of a note. An attacker with write access to a note can embed HTML t...Show more
HedgeDoc is a platform to write and share markdown. HedgeDoc before version 1.8.2 is vulnerable to a cross-site scripting attack using the YAML-metadata of a note. An attacker with write access to a note can embed HTML tags in the Open Graph metadata section of the note, resulting in the frontend rendering the script tag as part of the `<head>` section. Unless your instance prevents guests from editing notes, this vulnerability allows unauthenticated attackers to inject JavaScript into notes that allow guest edits. If your instance prevents guests from editing notes, this vulnerability allows authenticated attackers to inject JavaScript into any note pages they have write-access to. This vulnerability is patched in version 1.8.2. As a workaround, one can disable guest edits until the next update.Show less
1Ibm
1Control Center
Jun 17, 2026
May 19, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Control Center 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentia...Show more
IBM Control Center 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198761.Show less
1Ibm
1Maximo Asset Management
Jun 17, 2026
May 19, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia...Show more
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 195522.Show less
1Concerto Signage
1Concerto
Jun 17, 2026
May 19, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the First Name or Last Nam...Show more
Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote attacker to introduce arbitrary JavaScript by injecting an XSS payload into the First Name or Last Name parameter upon registration. When a privileged user attempts to delete the account, the XSS payload will be executed.Show less
1Bmc
1Remedy Mid Tier
Jul 9, 2026
May 19, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
BMC Remedy Mid Tier 9.1SP3 is affected by cross-site scripting (XSS). A DOM-based cross-site scripting vulnerability was discovered in a legacy utility.
1Issuehunt
1Boostnote
Jun 17, 2026
May 18, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Boostnote 0.12.1, exporting to PDF contains opportunities for XSS attacks.
1Tinyshop Project
1Tinyshop
Jun 17, 2026
May 18, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
TinyShop, a free and open source mall based on RageFrame2, has a stored XSS vulnerability that affects version 1.2.0. TinyShop allows XSS via the explain_first and again_explain parameters of the /evaluate/index.php page...Show more
TinyShop, a free and open source mall based on RageFrame2, has a stored XSS vulnerability that affects version 1.2.0. TinyShop allows XSS via the explain_first and again_explain parameters of the /evaluate/index.php page. The vulnerability may be exploited remotely, resulting in cross-site scripting (XSS) or information disclosure.Show less