← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Open Xchange
1Open Xchange Appsuite
Nov 21, 2024
Jan 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.22.4 before 6.22.4-rev12 allows remote attackers to inject arbitrary web script or HTML via the subje...Show more
Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.22.4 before 6.22.4-rev12 allows remote attackers to inject arbitrary web script or HTML via the subject of an email. NOTE: the vulnerabilities related to the body of the email and the publication name were SPLIT from this CVE ID because they affect different sets of versions.Show less
2Fedoraproject
Sensiolabs
2Fedora
Symfony
Nov 21, 2024
Jan 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generati...Show more
Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks.Show less
2Angularjs
Redhat
3Angularjs
Decision ManagerProcess Automation
Jun 17, 2026
Jan 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, with...Show more
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.Show less
3Knockoutjs
OracleRedhat
5Business Intelligence
Decision ManagerGoldengate+2 more
Jun 17, 2026
Jan 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without va...Show more
There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.Show less
1Opsview
2Opsview
Opsview Core
Nov 21, 2024
Jan 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 and Opsview Core before 20130522 allow remote attackers to inject arbitrary web script or HTML.
1Sitracker
1Support Incident Tracker
Jun 17, 2026
Jan 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a related issue to CVE-2012-2235.
1Sitracker
1Support Incident Tracker
Jun 17, 2026
Jan 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page are affected by XSS.
1Sitracker
1Support Incident Tracker
Jun 17, 2026
Jan 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS. The XSS payload is, for example, executed on the about.php page.
1Sitracker
1Support Incident Tracker
Jun 17, 2026
Jan 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected by XSS.
1Postieplugin
1Postie
Jun 17, 2026
Jan 2, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginning and a crafted SVG element.
1Zenphoto
1Zenphoto
Nov 21, 2024
Dec 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attackers to perform a cross-site scripting (XSS) attack by wrapping a payload in "<<script></script>script>...Show more
The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attackers to perform a cross-site scripting (XSS) attack by wrapping a payload in "<<script></script>script>payload<script></script></script>", or in an image tag, with the payload as the onerror event.Show less
1Zenphoto
1Zenphoto
Nov 21, 2024
Dec 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks.
1Fibranet
1Monitorix
Nov 21, 2024
Dec 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the handle_request function in lib/HTTPServer.pm in Monitorix before 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
1It Novum
1Openitcockpit
Jun 17, 2026
Dec 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.
1Fiberhomegroup
1An5506 04 F Firmware
Jun 17, 2026
Dec 31, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
FiberHome an5506-04-f RP2669 devices have XSS.
1Craftcms
1Craft Cms
Jun 17, 2026
Dec 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.
1Boltcms
1Bolt
Jun 17, 2026
Dec 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.
1Paessler
1Prtg Network Monitor
Jun 17, 2026
Dec 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PRTG Network Monitor v7.1.3.3378 allows XSS via the /search.htm searchtext parameter. NOTE: This product is discontinued.
1Paessler
1Prtg Network Monitor
Jun 17, 2026
Dec 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PRTG Network Monitor v7.1.3.3378 allows XSS via the /public/login.htm errormsg or loginurl parameter. NOTE: This product is discontinued.
1Metalgenix
1Genixcms
Nov 21, 2024
Dec 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GeniXCMS 1.1.5 has XSS via the dbuser or dbhost parameter during step 1 of installation.