← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Csshero
1Csshero
Jun 17, 2026
Dec 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page request because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this iss...Show more
The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page request because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary JavaScript in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookies or launch other attacks.Show less
1Davical
1Davical
Jun 17, 2026
Dec 4, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields that can be set by unprivileged users, making it possible for JavaScript stored in those fields to be e...Show more
A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields that can be set by unprivileged users, making it possible for JavaScript stored in those fields to be executed by another (possibly privileged) user. Affected database fields include Username, Display Name, and Email.Show less
1Qnap
1Qts
Jun 17, 2026
Dec 4, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an attacker to inject and execute scripts on the administrator console. T...Show more
A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an attacker to inject and execute scripts on the administrator console. To fix this vulnerability, QNAP recommend updating QTS to the latest version.Show less
2Emc
Rsa
2Authentication Manager
Rsa Authentication Manager
Jun 17, 2026
Dec 3, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the Security Console. A malicious Security Console administrator could exploit this vulnerability to sto...Show more
RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the Security Console. A malicious Security Console administrator could exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface which could then be included in a report. When other Security Console administrators open the affected report, the injected scripts could potentially be executed in their browser.Show less
1Saltosystem
1Proaccess Space
Jun 17, 2026
Dec 3, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SALTO ProAccess SPACE 5.4.3.0 allows XSS.
1Openwrt
1Openwrt
Jun 17, 2026
Dec 3, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OpenWrt 18.06.4 allows XSS via the "New port forward" Name field to the cgi-bin/luci/admin/network/firewall/forwards URI (this can occur, for example, on a TP-Link Archer C7 device).
1Openwrt
1Openwrt
Jun 17, 2026
Dec 3, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-bin/luci/admin/network/firewall/rules URI: "Open ports on router" and "New forward rule" and "New Source NAT" (this can occur, for example, on a TP-Link Archer...Show more
OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-bin/luci/admin/network/firewall/rules URI: "Open ports on router" and "New forward rule" and "New Source NAT" (this can occur, for example, on a TP-Link Archer C7 device).Show less
1Ibm
1Cloud Pak System
Jun 17, 2026
Dec 3, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to...Show more
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163777.Show less
1Ibm
1Cloud Pak System
Jun 17, 2026
Dec 3, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to...Show more
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163776.Show less
1Ibm
1Cloud Pak System
Jun 17, 2026
Dec 3, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to...Show more
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159243.Show less
1Ibm
1Cloud Pak System
Jun 17, 2026
Dec 3, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to...Show more
IBM Cloud Pak System 2.3 and 2.3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158020.Show less
2Redhat
Theforeman
2Katello
Satellite
Nov 21, 2024
Dec 3, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Katello has multiple XSS issues in various entities
1Piwigo
1Piwigo
Nov 21, 2024
Dec 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
piwigo has XSS in password.php (incomplete fix for CVE-2012-4525)
1Piwigo
1Piwigo
Nov 21, 2024
Dec 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
piwigo has XSS in password.php
1Alfresco
1Alfresco
Jun 17, 2026
Dec 2, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Alfresco Enterprise before 5.2.5 allows stored XSS via an uploaded HTML document.
1Testlink
1Testlink
Jun 17, 2026
Dec 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a lib/testcases/tcEdit.php?doAction=doDeleteStep request.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Nov 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the dialplan_uuid parameter.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Nov 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the c parameter.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Nov 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id and/or voicemail_id parameter...Show more
A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id and/or voicemail_id parameter.Show less
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Nov 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the app_uuid parameter.