← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Horde
2Debian Linux
Groupware
Nov 21, 2024
Nov 5, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
1Cryptocat Project
1Cryptocat
Nov 21, 2024
Nov 5, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting
1Typo3
1Typo3
Nov 21, 2024
Nov 4, 2019
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.
1Typo3
1Typo3
Nov 21, 2024
Nov 4, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the Extension Manager.
1Redhat
1Jboss Aerogear
Nov 21, 2024
Nov 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
JBoss AeroGear has reflected XSS via the password field
1Pfsense
1Pfsense Pkg Freeradius3
Jun 17, 2026
Nov 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
/usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payload as password or username to execute arbitrary javascript code on a victim brows...Show more
/usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payload as password or username to execute arbitrary javascript code on a victim browser.Show less
1Secudos
1Domos
Jun 17, 2026
Nov 2, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The Log module in SECUDOS DOMOS before 5.6 allows XSS.
3Debian
FedoraprojectSmokeping
3Debian Linux
FedoraSmokeping
Nov 21, 2024
Nov 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
1Avg
1Anti Virus
Jun 17, 2026
Nov 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross Site Scripting (XSS) issue exists in AVG AntiVirus (Internet Security Edition) 19.3.3084 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name.
1Avas!t
1Antivirus
Jun 17, 2026
Nov 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript cod...Show more
A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name.Show less
1Redhat
2Cloudforms
Manageiq Enterprise Virtualization Manager
Nov 21, 2024
Nov 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Typo3
1Typo3
Nov 21, 2024
Nov 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend.
1Websieve Project
1Websieve
Nov 20, 2024
Nov 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in websieve v0.62 allows remote attackers to inject arbitrary web script or HTML code in the web user interface.
1F5
13Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+10 more
Jun 17, 2026
Nov 1, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On BIG-IP 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI), also known as the...Show more
On BIG-IP 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI), also known as the BIG-IP Configuration utility.Show less
1Jitbit
1.net Forum
Jun 17, 2026
Nov 1, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in Jitbit .NET Forum (aka ASP.NET forum) 8.3.8 allows remote attackers to inject arbitrary web script or HTML via the gravatar URL parameter.
1Control Webpanel
1Webpanel
Jun 17, 2026
Oct 31, 2019
N/A· v4
4.6 MEDIUM· v3
1.9 LOW· v2
Stored XSS in filemanager2.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.885 exists via the cmd_arg parameter. This can be exploited by a local attacker who supplies a crafted filename within a directory vi...Show more
Stored XSS in filemanager2.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.885 exists via the cmd_arg parameter. This can be exploited by a local attacker who supplies a crafted filename within a directory visited by the victim.Show less
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Oct 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.
2Debian
Mantisbt
2Debian Linux
Mantisbt
Nov 21, 2024
Oct 31, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a comple...Show more
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a complex value.Show less
1Mantisbt
1Mantisbt
Nov 21, 2024
Oct 31, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via a project name.
2Fedoraproject
Mantisbt
2Fedora
Mantisbt
Nov 21, 2024
Oct 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in MantisBT 1.2.14 allows remote attackers to inject arbitrary web script or HTML via a version, related to deleting a version.