← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cleantalk
1Spam Protection, Antispam, Firewall
Jun 17, 2026
Nov 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till pa...Show more
The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter. The component is: inc/cleantalk-users.php and inc/cleantalk-comments.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.Show less
1Zen Project
1Zen
Nov 21, 2024
Nov 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the zen_breadcrumb function in template.php in the Zen theme 6.x-1.x, 7.x-3.x before 7.x-3.2, and 7.x-5.x before 7.x-5.4 for Drupal allows remote authenticated users with the "...Show more
Cross-site scripting (XSS) vulnerability in the zen_breadcrumb function in template.php in the Zen theme 6.x-1.x, 7.x-3.x before 7.x-3.2, and 7.x-5.x before 7.x-5.4 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via the breadcrumb separator field.Show less
1Bitweaver
1Bitweaver
Nov 21, 2024
Nov 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) stats/index.php or (2) newsletters/edition.php or...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) stats/index.php or (2) newsletters/edition.php or the (3) username parameter to users/remind_password.php, (4) days parameter to stats/index.php, (5) login parameter to users/register.php, or (6) highlight parameter.Show less
1Lavalite
1Lavalite
Jun 17, 2026
Nov 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS exists in Lavalite CMS 5.7 via the admin/profile name or designation field.
1Parallels
1Parallels Plesk Panel
Jun 17, 2026
Nov 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Parallels Plesk Panel 9.5 allows XSS in target/locales/tr-TR/help/index.htm? via the "fileName" parameter.
1Enghouse
1Web Chat
Jun 17, 2026
Nov 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. The QueueName parameter of a GET request allows for insertion of user-supplied JavaScript.
1Netgear
2Wnr3500l Firmware
Wnr3500u Firmware
Nov 21, 2024
Nov 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in NETGEAR WNR3500U and WNR3500L.
1Redhat
1Openshift Origin
Nov 21, 2024
Nov 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OpenShift Origin: Improperly validated team names could allow stored XSS attacks
2Debian
Trilexnet
2Debian Linux
Letodms
Nov 21, 2024
Nov 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar
1Fudforum
1Fudforum
Jun 17, 2026
Nov 13, 2019
N/A· v4
9.0 CRITICAL· v3
8.5 HIGH· v2
FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system using a POST request. When the admin visits...Show more
FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system using a POST request. When the admin visits the user information, the payload will execute. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.Show less
1Technicolor
1Tc7300.b0 Firmware
Jun 17, 2026
Nov 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the "Connected Clients" field to /wlanAccess.asp. An intranet host can use a crafted hostname to ex...Show more
An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the "Connected Clients" field to /wlanAccess.asp. An intranet host can use a crafted hostname to exploit this.Show less
1Technicolor
1Tc7300.b0 Firmware
Jun 17, 2026
Nov 13, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the FileName parameter to /FTPDiag.asp.
1Redhat
1Jboss Business Rules Management System
Nov 21, 2024
Nov 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID parameter.
1Tibco
1Ebx Add Ons
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
The Digital Asset Manager Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Af...Show more
The Digital Asset Manager Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions up to and including 3.20.13, versions 4.1.0, 4.2.0, 4.2.1, and 4.2.2.Show less
1Tibco
1Ebx Add Ons
Jun 17, 2026
Nov 12, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Data Exchange Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected r...Show more
The Data Exchange Web Interface component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that theoretically allows authenticated users to perform stored cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions up to and including 3.20.13, version 4.1.0.Show less
1Tibco
1Ebx
Jun 17, 2026
Nov 12, 2019
N/A· v4
9.6 CRITICAL· v3
4.3 MEDIUM· v2
The Web server component of TIBCO Software Inc.'s TIBCO EBX contains multiple vulnerabilities that theoretically allow authenticated users to perform stored cross-site scripting (XSS) attacks, and unauthenticated users t...Show more
The Web server component of TIBCO Software Inc.'s TIBCO EBX contains multiple vulnerabilities that theoretically allow authenticated users to perform stored cross-site scripting (XSS) attacks, and unauthenticated users to perform reflected cross-site scripting attacks. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions up to and including 5.8.1.fixR, versions 5.9.3, 5.9.4, 5.9.5, and 5.9.6.Show less
1Systematicinc
1Iris Standards Management
Jun 17, 2026
Nov 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Systematic IRIS Standards Management (ISM) v2.1 SP1 89 is vulnerable to unauthenticated reflected Cross Site Scripting (XSS). A user input (related to dialog information) is reflected directly in the web page, allowing a...Show more
Systematic IRIS Standards Management (ISM) v2.1 SP1 89 is vulnerable to unauthenticated reflected Cross Site Scripting (XSS). A user input (related to dialog information) is reflected directly in the web page, allowing a malicious user to conduct a Cross Site Scripting attack against users of the application.Show less
1Getigniteup
1Igniteup
Jun 17, 2026
Nov 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS.
1Status
1Statusnet
Nov 21, 2024
Nov 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
statusnet before 0.9.9 has XSS
1Elgg
1Elgg
Nov 21, 2024
Nov 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Elgg through 1.7.10 has XSS