CWE-79
46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,318)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cleantalk 1Spam Protection, Antispam, Firewall Jun 17, 2026 Nov 13, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till pa...Show more |
Cross-site scripting (XSS) vulnerability in the zen_breadcrumb function in template.php in the Zen theme 6.x-1.x, 7.x-3.x before 7.x-3.2, and 7.x-5.x before 7.x-5.4 for Drupal allows remote authenticated users with the "...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) stats/index.php or (2) newsletters/edition.php or...Show more |
XSS exists in Lavalite CMS 5.7 via the admin/profile name or designation field. |
1Parallels 1Parallels Plesk Panel Jun 17, 2026 Nov 13, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Parallels Plesk Panel 9.5 allows XSS in target/locales/tr-TR/help/index.htm? via the "fileName" parameter. |
An XSS issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. The QueueName parameter of a GET request allows for insertion of user-supplied JavaScript. |
1Netgear 2Wnr3500l Firmware Wnr3500u FirmwareNov 21, 2024 Nov 13, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in NETGEAR WNR3500U and WNR3500L. |
OpenShift Origin: Improperly validated team names could allow stored XSS attacks |
2Debian Trilexnet2Debian Linux LetodmsNov 21, 2024 Nov 13, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar |
FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system using a POST request. When the admin visits...Show more |
1Technicolor 1Tc7300.b0 Firmware Jun 17, 2026 Nov 13, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the "Connected Clients" field to /wlanAccess.asp. An intranet host can use a crafted hostname to ex...Show more |
1Technicolor 1Tc7300.b0 Firmware Jun 17, 2026 Nov 13, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the FileName parameter to /FTPDiag.asp. |
1Redhat 1Jboss Business Rules Management System Nov 21, 2024 Nov 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID parameter. |
The Digital Asset Manager Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Af...Show more |
The Data Exchange Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected r...Show more |
The Web server component of TIBCO Software Inc.'s TIBCO EBX contains multiple vulnerabilities that theoretically allow authenticated users to perform stored cross-site scripting (XSS) attacks, and unauthenticated users t...Show more |
1Systematicinc 1Iris Standards Management Jun 17, 2026 Nov 12, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Systematic IRIS Standards Management (ISM) v2.1 SP1 89 is vulnerable to unauthenticated reflected Cross Site Scripting (XSS). A user input (related to dialog information) is reflected directly in the web page, allowing a...Show more |
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS. |
statusnet before 0.9.9 has XSS |
Elgg through 1.7.10 has XSS |