← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Jboss Keycloak
Nov 21, 2024
Dec 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JBoss KeyCloak: XSS in login-status-iframe.html
1Ibm
1Planning Analytics
Jun 17, 2026
Dec 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentia...Show more
IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 168519.Show less
1Ibm
1Watson Assistant For Ibm Cloud Pak For Data
Jun 17, 2026
Dec 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Watson Assistant for IBM Cloud Pak for Data 1.0.0 through 1.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended funct...Show more
IBM Watson Assistant for IBM Cloud Pak for Data 1.0.0 through 1.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162807.Show less
1Accentis
1Content Resource Management System
Nov 21, 2024
Dec 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Accentis Content Resource Management System before October 2015 patch allows remote attackers to inject arbitrary web script or HTML via the ctl00$cph_content$_uig_formState pa...Show more
Cross-site scripting (XSS) vulnerability in Accentis Content Resource Management System before October 2015 patch allows remote attackers to inject arbitrary web script or HTML via the ctl00$cph_content$_uig_formState parameter.Show less
1Nopcommerce
1Nopcommerce
Jun 17, 2026
Dec 9, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
nopCommerce through 4.20 allows XSS in the SaveStoreMappings of the components \Presentation\Nop.Web\Areas\Admin\Controllers\NewsController.cs and \Presentation\Nop.Web\Areas\Admin\Controllers\BlogController.cs via Body...Show more
nopCommerce through 4.20 allows XSS in the SaveStoreMappings of the components \Presentation\Nop.Web\Areas\Admin\Controllers\NewsController.cs and \Presentation\Nop.Web\Areas\Admin\Controllers\BlogController.cs via Body or Full to Admin/News/NewsItemEdit/[id] Admin/Blog/BlogPostEdit/[id]. NOTE: the vendor reportedly considers this a "feature" because the affected components are an HTML content editor.Show less
1Xpand It
1Xray Test Mangaement
Jun 17, 2026
Dec 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the Pre-Condition Summary entry point via the summary field of a Create Pre-Condition action for a new Test Issue...Show more
In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the Pre-Condition Summary entry point via the summary field of a Create Pre-Condition action for a new Test Issue.Show less
1Xpand It
1Xray Test Mangaement
Jun 17, 2026
Dec 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the generic field entry point via the Generic Test Definition field of a new Generic Test issue.
1Serialize To Js Project
1Serialize To Js
Jun 17, 2026
Dec 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The serialize-to-js NPM package before version 3.0.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulnerability is not affec...Show more
The serialize-to-js NPM package before version 3.0.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulnerability is not affected on Node.js environment since Node.js's implementation of RegExp.prototype.toString() backslash-escapes all forward slashes in regular expressions. If serialized data of regular expression objects are used in an environment other than Node.js, it is affected by this vulnerability.Show less
1Sangoma
1Freepbx
Jun 17, 2026
Dec 6, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the user management screen of the Administrator web site, i.e., the/admin/config.php?display=userman URI. An attacker with sufficient privileges can...Show more
In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the user management screen of the Administrator web site, i.e., the/admin/config.php?display=userman URI. An attacker with sufficient privileges can edit the Display Name of a user and embed malicious XSS code. When another user (such as an admin) visits the main User Management screen, the XSS payload will render and execute in the context of the victim user's account.Show less
1Sangoma
1Freepbx
Jun 17, 2026
Dec 6, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the User Management screen of the Administrator web site. An attacker with access to the User Control Panel application can submit malicious values...Show more
In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the User Management screen of the Administrator web site. An attacker with access to the User Control Panel application can submit malicious values in some of the time/date formatting and time-zone fields. These fields are not being properly sanitized. If this is done and a user (such as an admin) visits the User Management screen and views that user's profile, the XSS payload will render and execute in the context of the victim user's account.Show less
1Documize
1Documize
Jun 17, 2026
Dec 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
domain/section/markdown/markdown.go in Documize before 3.5.1 mishandles untrusted Markdown content. This was addressed by adding the bluemonday HTML sanitizer to defend against XSS.
3Debian
FedoraprojectLdap Account Manager
3Debian Linux
FedoraLdap Account Manager
Nov 21, 2024
Dec 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.
3Debian
FedoraprojectLdap Account Manager
3Debian Linux
FedoraLdap Account Manager
Nov 21, 2024
Dec 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.
1Verizon
1Serialize Javascript
Jun 17, 2026
Dec 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The serialize-javascript npm package before version 2.1.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulnerability is not...Show more
The serialize-javascript npm package before version 2.1.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulnerability is not affected on Node.js environment since Node.js's implementation of RegExp.prototype.toString() backslash-escapes all forward slashes in regular expressions. If serialized data of regular expression objects are used in an environment other than Node.js, it is affected by this vulnerability.Show less
1Qnap
1Music Station
Jun 17, 2026
Dec 5, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music Sta...Show more
This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music Station to their latest versions.Show less
1Qnap
1Video Station
Jun 17, 2026
Dec 5, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Video Sta...Show more
This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Video Station to their latest versions.Show less
1Sceditor
1Sceditor
Jun 17, 2026
Dec 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SCEditor 2.1.3 allows XSS.
1Theforeman
1Katello
Nov 21, 2024
Dec 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Katello: Username in Notification page has cross site scripting
1Gitbook
1Gitbook
Jun 17, 2026
Dec 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
GitBook through 2.6.9 allows XSS via a local .md file.
1Wso2
1Enterprise Integrator
Jun 17, 2026
Dec 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In WSO2 Enterprise Integrator 6.5.0, reflected XSS occurs when updating the message processor configuration from the source view in the Management Console.