← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Nov 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the fax_uuid parameter.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Nov 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Nov 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.
1Ulli Horlacher
1Fex
Nov 21, 2024
Nov 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The addto parameter to fup in Frams' Fast File EXchange (F*EX, aka fex) before fex-2014053 allows remote attackers to conduct cross-site scripting (XSS) attacks
1Wikimedia
1Wikidata Query Gui
Jun 17, 2026
Nov 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are displayed directly, arbitrary JavaScript execution can occur, aka XSS. This was addressed by introduci...Show more
In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are displayed directly, arbitrary JavaScript execution can occur, aka XSS. This was addressed by introducing MathJax as a new mathematics rendering engine. NOTE: this GUI code is no longer bundled with the Wikibase Wikidata Query Service snapshots, such as 0.3.6-SNAPSHOT.Show less
1Wikimedia
1Wikidata Query Gui
Jun 17, 2026
Nov 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ui/editor/tooltip/Rdf.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection in tooltips for entities. NOTE: this GUI code is no longer bundled with the Wikibase Wikidata Query S...Show more
ui/editor/tooltip/Rdf.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection in tooltips for entities. NOTE: this GUI code is no longer bundled with the Wikibase Wikidata Query Service snapshots, such as 0.3.6-SNAPSHOT.Show less
1Wikimedia
1Wikidata Query Gui
Jun 17, 2026
Nov 27, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ui/ResultView.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection when reporting the number of results and number of milliseconds. NOTE: this GUI code is no longer bundled wit...Show more
ui/ResultView.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection when reporting the number of results and number of milliseconds. NOTE: this GUI code is no longer bundled with the Wikibase Wikidata Query Service snapshots, such as 0.3.6-SNAPSHOT.Show less
1Siemens
1Polarion
Jun 17, 2026
Nov 27, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a persistent XSS vulnerability. This issue affects...Show more
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a persistent XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.Show less
1Siemens
1Polarion
Jun 17, 2026
Nov 27, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects:...Show more
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.Show less
1Siemens
1Polarion
Jun 17, 2026
Nov 27, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects:...Show more
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Siemens AG Polarion could allow an attacker to exploit a reflected XSS vulnerability. This issue affects: Siemens AG Polarion All versions < 19.2.Show less
1Centreon
1Centreon
Jun 17, 2026
Nov 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields.
1Gitlab
1Gitlab
Jun 17, 2026
Nov 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature. It has XSS.
1Cloudera
1Cloudera Manager
Jun 17, 2026
Nov 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious impala queries can result in Cross Site Scripting (XSS) when viewed within this product.
1Afterlogic
2Aurora
Webmail Pro
Jun 17, 2026
Nov 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Afterlogic WebMail Pro 8.3.11, and WebMail in Afterlogic Aurora 8.3.11, allows Remote Stored XSS via an attachment name.
1Cloudera
1Cloudera Manager
Nov 21, 2024
Nov 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature.
1Zoho
1Lead Magnet
Jun 17, 2026
Nov 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Nov 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.
1Fast Secure Contact Form Project
1Fast Secure Contact Form
Nov 21, 2024
Nov 26, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Fast Secure Contact Form plugin before 4.0.38 for WordPress allows fs_contact_form1[welcome] XSS.
1Imagely
1Nextgen Gallery
Nov 21, 2024
Nov 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The NextGEN Gallery plugin before 2.1.10 for WordPress has multiple XSS issues involving thumbnail_width, thumbnail_height, thumbwidth, thumbheight, wmXpos, and wmYpos, and template.
1Cloudera
1Cloudera Manager
Nov 21, 2024
Nov 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in the Cloudera Manager UI before 5.4.3 allow remote authenticated users to inject arbitrary web script or HTML using unspecified vectors.