← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pimcore
1Pimcore
Jun 17, 2026
Oct 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translations.js mishandles certain HTML elements.
1Jupyter
1Notebook
Nov 21, 2024
Oct 31, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.
1Apakgroup
1Wholesale Floorplanning Finance
Jun 17, 2026
Oct 31, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Apak Wholesale Floorplanning Finance 6.31.8.3 and 6.31.8.5, an attacker can send an authenticated POST request with a malicious payload to /WFS/agreementView.faces allowing a stored XSS via the mainForm:loanNotesnotes...Show more
In Apak Wholesale Floorplanning Finance 6.31.8.3 and 6.31.8.5, an attacker can send an authenticated POST request with a malicious payload to /WFS/agreementView.faces allowing a stored XSS via the mainForm:loanNotesnotes:0:rich_text_editor_note_text parameter in the Notes section. Although versions 6.31.8.3 and 6.31.8.5 are confirmed to be affected, all versions with the vulnerable WYSIWYG editor in the Notes section are likely affected.Show less
1Ikiwiki
1Ikiwiki
Nov 21, 2024
Oct 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in ikiwiki before 3.20101112 allows remote attackers to inject arbitrary web script or HTML via a comment.
1Apache
1Airflow
Jun 17, 2026
Oct 30, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readabl...Show more
A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readable by the webserver process.Show less
1Zucchetti
1Infobusiness
Jun 17, 2026
Oct 30, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper validation of the Title field in the InfoBusiness Web Component. The payload will be triggered every...Show more
In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper validation of the Title field in the InfoBusiness Web Component. The payload will be triggered every time a user browses the reports page.Show less
1Zucchetti
1Infobusiness
Jun 17, 2026
Oct 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did not properly sanitize user input (encoded in base64). This also applies...Show more
Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did not properly sanitize user input (encoded in base64). This also applies to the search functionality for the searchKey parameter.Show less
1Sir
1Gnuboard
Nov 21, 2024
Oct 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board group extra contents" parameter, aka the adm/boardgroup_form_update.php gr_1~10 parameter.
1Labkey
1Labkey Server
Jun 17, 2026
Oct 29, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in LabKey Server 19.1.0. The display name of a user is vulnerable to stored XSS that can execute on administrators from security/permissions.view, security/addUsers.view, or wiki/Administration/pa...Show more
An issue was discovered in LabKey Server 19.1.0. The display name of a user is vulnerable to stored XSS that can execute on administrators from security/permissions.view, security/addUsers.view, or wiki/Administration/page.view in the admin panel, leading to privilege escalation.Show less
1Sahipro
1Sahi Pro
Jun 17, 2026
Oct 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updating a script's Script Name, Suite Name, Base URL, Android, iOS, Scripts R...Show more
Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updating a script's Script Name, Suite Name, Base URL, Android, iOS, Scripts Run, Origin Machine, or Comment field. The sql parameter can be used to trigger reflected XSS.Show less
1Fabrikar
1Fabrik
Nov 21, 2024
Oct 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected Cross-Site Scripting (XSS) vulnerability in the fabrik_referrer hidden field in the Fabrikar Fabrik component through v3.8.1 for Joomla! allows remote attackers to inject arbitrary web script via the HTTP Refer...Show more
Reflected Cross-Site Scripting (XSS) vulnerability in the fabrik_referrer hidden field in the Fabrikar Fabrik component through v3.8.1 for Joomla! allows remote attackers to inject arbitrary web script via the HTTP Referer header.Show less
1Ikiwiki
1Ikiwiki
Nov 21, 2024
Oct 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) in ikiwiki before 3.20110122 could allow remote attackers to insert arbitrary JavaScript due to insufficient checking in comments.
1Translatehouse
1Pootle
Nov 21, 2024
Oct 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
pootle 2.0.5 has XSS via 'match_names' parameter
1Tiki
1Tikiwiki Cms/groupware
Nov 21, 2024
Oct 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Tiki Wiki CMS Groupware 5.2 has XSS
1Pixelpost
1Pixelpost
Nov 21, 2024
Oct 28, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
pixelpost 1.7.1 has XSS
2Inea
Mitsubishielectric
2Me Rtu Firmware
Smartrtu Firmware
Jun 17, 2026
Oct 28, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-site script (XSS) vulnerabilities allow an attacker to inject malicious...Show more
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-site script (XSS) vulnerabilities allow an attacker to inject malicious code directly into the application. An example input variable vulnerable to stored XSS is SerialInitialModemString in the index.php page.Show less
1Corehr
1Core Portal
Jun 17, 2026
Oct 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
CoreHR Core Portal before 27.0.7 allows stored XSS.
1Adobe
1Experience Manager
Jun 17, 2026
Oct 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a reflected cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
1Adobe
1Experience Manager
Jun 17, 2026
Oct 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a reflected cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
1Adobe
1Experience Manager
Jun 17, 2026
Oct 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Experience Manager versions 6.5, 6.4 and 6.3 have a cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.