CWE-79
46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,318)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field. |
1Tibco 2Spotfire Analytics Platform For Aws Spotfire ServerJun 17, 2026 Dec 17, 2019 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker to perform a reflecte...Show more |
MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message. |
Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php. |
2Debian Mahara2Debian Linux MaharaNov 21, 2024 Dec 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as use...Show more |
1Jenkins 1Pipeline Aggregator View Jun 17, 2026 Dec 17, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Jenkins Pipeline Aggregator View Plugin 1.8 and earlier does not escape information shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to affects view content such as job display nam...Show more |
Jenkins Mission Control Plugin 0.9.16 and earlier does not escape job display names and build names shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to change these properties. |
Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the description of builds shown in its view, resulting in a stored XSS vulnerability exploitable by users able to change build descriptions. |
A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7. |
A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker can exploit it by sending a crafted link to end users and can execute arbitrary Javascripts |
2Debian Zend2Debian Linux Zend FrameworkNov 21, 2024 Dec 15, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 ZF2014-03 has a potential cross site scripting vector in multiple view helpers |
1Ibm 2Business Automation Workflow Case ManagerJun 17, 2026 Dec 13, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The Case Builder component shipped with 18.0.0.1 through 19.0.0.2 and IBM Case Manager 5.1.1 through 5.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We...Show more |
TemaTres 3.0 has reflected XSS via the replace_string or search_string parameter to the vocab/admin.php?doAdmin=bulkReplace URI. |
1Expresstech 1Quiz And Survey Master Jun 17, 2026 Dec 13, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from...Show more |
1Siemens 5En100 Ethernet Module With Firmware Variant Dnp3 Tcp En100 Ethernet Module With Firmware Variant Iec104En100 Ethernet Module With Firmware Variant Iec 61850+2 moreJun 17, 2026 Dec 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Etherne...Show more |
A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow for an an attacker to craft the input in a form that is not expected, causing the application to behave in unexpected wa...Show more |
The Scoutnet Kalender plugin 1.1.0 for WordPress allows XSS. |
2Davical Debian2Davical Debian LinuxJun 17, 2026 Dec 12, 2019 N/A· v4 9.3 CRITICAL· v3 4.3 MEDIUM· v2 A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as we...Show more |
Intesync Solismed 3.3sp has XSS. |
A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to conduct cross site scripting attacks and gain access to unauthorized in...Show more |