← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Brizoit
1Work Time Calendar
Jun 17, 2026
Dec 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Work Time Calendar app before 4.7.1 for Jira allows XSS.
1Avaya
1Ip Office Application Server
Jun 17, 2026
Dec 12, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potentially disclose sensitive information. All product versions 11.x are affe...Show more
A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potentially disclose sensitive information. All product versions 11.x are affected. Product versions prior to 11.0, including unsupported versions, were not evaluated.Show less
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Dec 11, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScript in a text module in Fiori BI Launchpad, leading to Stored Cross Site Scripting vulnerability.
1Cart66
1Cart66 Lite Plugin
Nov 21, 2024
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Product name or (2) Pr...Show more
Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Product name or (2) Price description fields via a request to wp-admin/admin.php. NOTE: This issue may only cross privilege boundaries if used in combination with CVE-2013-5977.Show less
1Mediawiki
1Mediawiki
Nov 21, 2024
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not properly detect extensions when there are an even number of "." (period) ch...Show more
includes/libs/IEUrlExtension.php in the MediaWiki API in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 does not properly detect extensions when there are an even number of "." (period) characters in a string, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the siprop parameter in a query action to wiki/api.php.Show less
1Puppet
1Puppet Enterprise
Nov 21, 2024
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors relate...Show more
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."Show less
1Symantec
1Messaging Gateway
Jun 17, 2026
Dec 11, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other use...Show more
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.Show less
1Svg Sanitizer Project
1Svg Sanitizer
Jun 17, 2026
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
It is possible to bypass enshrined/svg-sanitize before 0.13.1 using the "xlink:href" attribute due to mishandling of the xlink namespace by the sanitizer.
1Ibm
1Spectrum Scale
Jun 17, 2026
Dec 11, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Spectrum Scale 4.2 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to crede...Show more
IBM Spectrum Scale 4.2 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171247.Show less
1Atlassian
2Crucible
Fisheye
Jun 17, 2026
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the revie...Show more
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the reviewedBranch parameter.Show less
1Atlassian
2Crucible
Fisheye
Jun 17, 2026
Dec 11, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branc...Show more
The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branch.Show less
2Debian
Sencha
2Connect
Debian Linux
Nov 21, 2024
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370)
4Debian
OpensuseRedhat+1 more
4Connect
Debian LinuxOpenshift+1 more
Nov 21, 2024
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
1Redhat
2Jboss Enterprise Application Platform
Jboss Portal
Nov 21, 2024
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JBossWeb Bayeux has reflected XSS
3Debian
FedoraprojectSmokeping
3Debian Linux
FedoraSmokeping
Nov 21, 2024
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
1Tableau
1Tableau Server
Jun 17, 2026
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page.
1Mediawiki
1Visual Editor
Jun 17, 2026
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve-clipboard-key attribute.
1Microsoft
3Power Bi Report Server
Sql Server 2017 Reporting ServicesSql Server 2019 Reporting Services
Jun 17, 2026
Dec 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Repor...Show more
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'.Show less
4Debian
FedoraprojectGoogle+1 more
7Chrome
Debian LinuxEnterprise Linux Desktop+4 more
Jun 17, 2026
Dec 10, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content.
1Ibm
1Websphere Application Server
Jun 17, 2026
Dec 10, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially lead...Show more
IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171245.Show less