CWE-79
46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,318)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Open Xchange 1Open Xchange Appsuite Nov 21, 2024 Jan 2, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.22.4 before 6.22.4-rev12 allows remote attackers to inject arbitrary web script or HTML via the subje...Show more |
2Fedoraproject Sensiolabs2Fedora SymfonyNov 21, 2024 Jan 2, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generati...Show more |
2Angularjs Redhat3Angularjs Decision ManagerProcess AutomationJun 17, 2026 Jan 2, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, with...Show more |
3Knockoutjs OracleRedhat5Business Intelligence Decision ManagerGoldengate+2 moreJun 17, 2026 Jan 2, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without va...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 and Opsview Core before 20130522 allow remote attackers to inject arbitrary web script or HTML. |
1Sitracker 1Support Incident Tracker Jun 17, 2026 Jan 2, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a related issue to CVE-2012-2235. |
1Sitracker 1Support Incident Tracker Jun 17, 2026 Jan 2, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page are affected by XSS. |
1Sitracker 1Support Incident Tracker Jun 17, 2026 Jan 2, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS. The XSS payload is, for example, executed on the about.php page. |
1Sitracker 1Support Incident Tracker Jun 17, 2026 Jan 2, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected by XSS. |
The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginning and a crafted SVG element. |
The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attackers to perform a cross-site scripting (XSS) attack by wrapping a payload in "<<script></script>script>...Show more |
Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks. |
Cross-site scripting (XSS) vulnerability in the handle_request function in lib/HTTPServer.pm in Monitorix before 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. |
openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component. |
1Fiberhomegroup 1An5506 04 F Firmware Jun 17, 2026 Dec 31, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 FiberHome an5506-04-f RP2669 devices have XSS. |
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI. |
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933. |
1Paessler 1Prtg Network Monitor Jun 17, 2026 Dec 31, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PRTG Network Monitor v7.1.3.3378 allows XSS via the /search.htm searchtext parameter. NOTE: This product is discontinued. |
1Paessler 1Prtg Network Monitor Jun 17, 2026 Dec 31, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 PRTG Network Monitor v7.1.3.3378 allows XSS via the /public/login.htm errormsg or loginurl parameter. NOTE: This product is discontinued. |
GeniXCMS 1.1.5 has XSS via the dbuser or dbhost parameter during step 1 of installation. |