← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dlink
1Dir 615 Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field.
1Tibco
2Spotfire Analytics Platform For Aws
Spotfire Server
Jun 17, 2026
Dec 17, 2019
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker to perform a reflecte...Show more
The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker to perform a reflected cross-site scripting (XSS) attack. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace: version 10.6.0 and TIBCO Spotfire Server: versions 7.11.7 and below, versions 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.0.1, 10.1.0, 10.2.0, 10.2.1, 10.3.0, 10.3.1, 10.3.2, 10.3.3, and 10.3.4, versions 10.4.0, 10.5.0, and 10.6.0.Show less
1Altn
1Mdaemon Email Server
Jun 17, 2026
Dec 17, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message.
1Owncloud
1Owncloud Server
Mar 31, 2025
Dec 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php.
2Debian
Mahara
2Debian Linux
Mahara
Nov 21, 2024
Dec 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as use...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms, (2) links or (3) resources URLs, and (4) the Display name in a user profile.Show less
1Jenkins
1Pipeline Aggregator View
Jun 17, 2026
Dec 17, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Pipeline Aggregator View Plugin 1.8 and earlier does not escape information shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to affects view content such as job display nam...Show more
Jenkins Pipeline Aggregator View Plugin 1.8 and earlier does not escape information shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to affects view content such as job display name or pipeline stage names.Show less
1Jenkins
1Mission Control
Jun 17, 2026
Dec 17, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Mission Control Plugin 0.9.16 and earlier does not escape job display names and build names shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to change these properties.
1Jenkins
1Buildgraph View
Jun 17, 2026
Dec 17, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the description of builds shown in its view, resulting in a stored XSS vulnerability exploitable by users able to change build descriptions.
1Solarwinds
1Serv U Ftp Server
Jun 17, 2026
Dec 16, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.
1Maxum
1Rumpus
Jun 17, 2026
Dec 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker can exploit it by sending a crafted link to end users and can execute arbitrary Javascripts
2Debian
Zend
2Debian Linux
Zend Framework
Nov 21, 2024
Dec 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ZF2014-03 has a potential cross site scripting vector in multiple view helpers
1Ibm
2Business Automation Workflow
Case Manager
Jun 17, 2026
Dec 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Case Builder component shipped with 18.0.0.1 through 19.0.0.2 and IBM Case Manager 5.1.1 through 5.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We...Show more
The Case Builder component shipped with 18.0.0.1 through 19.0.0.2 and IBM Case Manager 5.1.1 through 5.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162772.Show less
1Vocabularyserver
1Tematres
Jun 17, 2026
Dec 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
TemaTres 3.0 has reflected XSS via the replace_string or search_string parameter to the vocab/admin.php?doAdmin=bulkReplace URI.
1Expresstech
1Quiz And Survey Master
Jun 17, 2026
Dec 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from...Show more
The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The component is: admin/quiz-options-page.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.Show less
1Siemens
5En100 Ethernet Module With Firmware Variant Dnp3 Tcp
En100 Ethernet Module With Firmware Variant Iec104En100 Ethernet Module With Firmware Variant Iec 61850+2 more
Jun 17, 2026
Dec 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Etherne...Show more
A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions). The web interface could allow Cross-Site Scripting (XSS) attacks if an attacker is able to modify content of particular web pages, causing the application to behave in unexpected ways for legitimate users. Successful exploitation does not require for an attacker to be authenticated to the web interface. This could allow the attacker to read or modify contents of the web application. At the time of advisory publication no public exploitation of this security. vulnerability was known.Show less
1Siemens
1Xhq
Jun 17, 2026
Dec 12, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow for an an attacker to craft the input in a form that is not expected, causing the application to behave in unexpected wa...Show more
A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow for an an attacker to craft the input in a form that is not expected, causing the application to behave in unexpected ways for legitimate users. Successful exploitation requires for an attacker to be authenticated to the web interface. A successful attack could cause the application to have unexpected behavior. This could allow the attacker to modify contents of the web application. At the time of advisory publication no public exploitation of this security vulnerability was known.Show less
1Scoutnet
1Kalender
Jun 17, 2026
Dec 12, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Scoutnet Kalender plugin 1.1.0 for WordPress allows XSS.
2Davical
Debian
2Davical
Debian Linux
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.3 CRITICAL· v3
4.3 MEDIUM· v2
A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as we...Show more
A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrator, the attacker can for example add a new admin user to gain full access to the application.Show less
1Intesync
1Solismed
Jun 17, 2026
Dec 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Intesync Solismed 3.3sp has XSS.
1Redhat
13scale
Jun 17, 2026
Dec 12, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized in...Show more
A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized information.Show less