← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wso2
1Identity Server
Jun 17, 2026
Nov 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WSO2 IS as Key Manager 5.7.0 allows stored XSS in download-userinfo.jag because Content-Type is mishandled.
1Wso2
1Identity Server
Jun 17, 2026
Nov 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WSO2 IS as Key Manager 5.7.0 allows unauthenticated reflected XSS in the dashboard user profile.
1Fudforum
1Fudforum
Jun 17, 2026
Nov 12, 2019
N/A· v4
9.0 CRITICAL· v3
8.5 HIGH· v2
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET request. When the admin vis...Show more
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET request. When the admin visits user information under "User Manager" in the control panel, the payload will execute. This will allow for PHP files to be written to the web root, and for code to execute on the remote server. The problem is in admsession.php and admuser.php.Show less
1Svg Sanitizer Project
1Svg Sanitizer
Jun 17, 2026
Nov 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
darylldoyle svg-sanitizer before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected whitespace such as in the javascript	:alert substring.
1Mantisbt
1Mantisbt
Nov 21, 2024
Nov 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME types. Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks.
1Ibm
1Cognos Analytics
Jun 17, 2026
Nov 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to c...Show more
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170881.Show less
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Nov 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr...Show more
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 167239.Show less
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Nov 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr...Show more
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163779.Show less
1Ibm
1Qradar Security Information And Event Manager
Jun 17, 2026
Nov 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr...Show more
IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163618.Show less
1Ibm
1I
Jun 17, 2026
Nov 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden...Show more
IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163492.Show less
3Netapp
OracleRedhat
189Access Manager
Active Iq Unified ManagerAgile Engineering Data Management+186 more
Aug 25, 2026
Nov 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can r...Show more
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.Show less
1Sir
1Gnuboard
Nov 21, 2024
Nov 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board tail contents" parameter, aka the adm/board_form_update.php bo_content_tail parameter.
1Mahara
1Mahara
Nov 21, 2024
Nov 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web script or HTML via the TinyMCE editor.
1Drupal
1Drupal
Nov 21, 2024
Nov 7, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacke...Show more
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.Show less
1Drupal
1Drupal
Nov 21, 2024
Nov 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
1Popojicms
1Popojicms
Jun 17, 2026
Nov 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
po-admin/route.php?mod=post&act=edit in PopojiCMS 2.0.1 allows post[1][content]= stored XSS.
1Intelbras
1Wrn 150 Firmware
Jun 17, 2026
Nov 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered on Intelbras WRN 150 1.0.17 devices. There is stored XSS in the Service Name tab of the WAN configuration screen, leading to a denial of service (inability to change the configuration).
1Portainer
1Portainer
Jun 17, 2026
Nov 7, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Portainer before 1.22.1 has XSS (issue 2 of 2).
1Portainer
1Portainer
Jun 17, 2026
Nov 7, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Portainer before 1.22.1 has XSS (issue 1 of 2).
2Debian
Eclipse
2Debian Linux
Jetty
Nov 21, 2024
Nov 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.