← Back
CWE-79

48,005 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (48,005)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dedecms
1Dedecms
Jun 17, 2026
May 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyword parameter.
1Tp Link
1Archer C1200 Firmware
Jun 17, 2026
May 14, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
TP-Link Archer C1200 firmware version 1.13 Build 2018/01/24 rel.52299 EU has a XSS vulnerability allowing a remote attacker to execute arbitrary code.
1Haml Coffee Project
1Haml Coffee
Jun 17, 2026
May 14, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
haml-coffee is a JavaScript templating solution. haml-coffee mixes pure template data with engine configuration options through the Express render API. More specifically, haml-coffee supports overriding a series of HTML...Show more
haml-coffee is a JavaScript templating solution. haml-coffee mixes pure template data with engine configuration options through the Express render API. More specifically, haml-coffee supports overriding a series of HTML helper functions through its configuration options. A vulnerable application that passes user controlled request objects to the haml-coffee template engine may introduce RCE vulnerabilities. Additionally control over the escapeHtml parameter through template configuration pollution ensures that haml-coffee would not sanitize template inputs that may result in reflected Cross Site Scripting attacks against downstream applications. There is currently no fix for these issues as of the publication of this CVE. The latest version of haml-coffee is currently 1.14.1. For complete details refer to the referenced GHSL-2021-025.Show less
1Ibm
1Qradar User Behavior Analytics
Jun 17, 2026
May 14, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM QRadar User Behavior Analytics 1.0.0 through 4.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality pote...Show more
IBM QRadar User Behavior Analytics 1.0.0 through 4.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.Show less
1Yfcmf
1Yfcmf
Jun 17, 2026
May 14, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In YFCMF v2.3.1, there is a stored XSS vulnerability in the comments section of the news page.
1Laobancms
1Laobancms
Jun 17, 2026
May 14, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Homepage Introduction" field of component "admin/info.php?shuyu".
110web
1Photo Gallery
Jun 17, 2026
May 14, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to t...Show more
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cross-Site Scripting (XSS) issues via the gallery_id, tag, album_id and _id GET parameters passed to the bwg_frontend_data AJAX action (available to both unauthenticated and authenticated users)Show less
1Mooveagency
1Select All Categories And Taxonomies, Change Checkbox To Radio Buttons
Jun 17, 2026
May 14, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected...Show more
The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issueShow less
1Mooveagency
1Redirect 404 To Parent
Jun 17, 2026
May 14, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue
1Pickplugins
1Accordion
Jun 17, 2026
May 14, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The tab GET parameter of the settings page is not sanitised or escaped when being output back in an HTML attribute, leading to a reflected XSS issue.
1Wpuslugi
1Rss For Yandex Turbo
Jun 17, 2026
May 14, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The RSS for Yandex Turbo WordPress plugin before 1.30 did not properly sanitise the user inputs from its Счетчики settings tab before outputting them back in the page, leading to authenticated stored Cross-Site Scripting...Show more
The RSS for Yandex Turbo WordPress plugin before 1.30 did not properly sanitise the user inputs from its Счетчики settings tab before outputting them back in the page, leading to authenticated stored Cross-Site Scripting issuesShow less
1Bluespire
1Aurelia Framework
Jun 17, 2026
May 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnerable to XSS. The sanitizer only attempts to filter SCRIPT elements, which makes it feasible for remot...Show more
The HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnerable to XSS. The sanitizer only attempts to filter SCRIPT elements, which makes it feasible for remote attackers to conduct XSS attacks via (for example) JavaScript code in an attribute of various other elements. An attacker might also exploit a bug in how the SCRIPT string is processed by splitting and nesting them for example.Show less
1Wago
50852 0303 Firmware
0852 1305/000 001 Firmware0852 1305 Firmware+2 more
Jun 17, 2026
May 13, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In multiple managed switches by WAGO in different versions an attacker may trick a legitimate user to click a link to inject possible malicious code into the Web-Based Management.
1Deskpro
1Deskpro
Jun 17, 2026
May 12, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templates.
1Laobancms
1Laobancms
Jun 17, 2026
May 12, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Website SEO Keywords" field on the page "admin/info.php?shuyu".
1Eng
1Knowage
Jun 17, 2026
May 12, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Knowage Suite 7.3 is vulnerable to unauthenticated reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in '/servlet/AdapterHTTP' via the 'targetService' parameter.
1Eng
1Knowage
Jun 17, 2026
May 12, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/documentnotes/saveNote' via the 'nota' parameter.
1Eng
1Knowage
Jun 17, 2026
May 12, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Knowage Suite 7.3 is vulnerable to Stored Cross-Site Scripting (XSS). An attacker can inject arbitrary web script in '/knowage/restful-services/signup/update' via the 'surname' parameter.
1Dhcms Project
1Dhcms
Jun 17, 2026
May 12, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross SIte Scripting (XSS) vulnerability exists in Dhcms 2017-09-18 in guestbook via the message board, which could let a remote malicious user execute arbitrary code.
1Solarwinds
1Serv U
Jun 17, 2026
May 11, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share URL XSS."