← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Clonos
1Clonos
Jun 17, 2026
Oct 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in index.php in ClonOS WEB control panel 19.09 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
1Adobe
1Experience Manager
Jun 17, 2026
Oct 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Experience Manager versions 6.4 and 6.3 have a stored cross site scripting vulnerability. Successful exploitation could lead to privilege escalation.
1Adobe
1Experience Manager
Jun 17, 2026
Oct 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
1Adobe
1Experience Manager
Jun 17, 2026
Oct 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a reflected cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
1Restaurant Management System Project
1Restaurant Management System
Jun 17, 2026
Oct 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Sourcecodester Restaurant Management System 1.0 allows XSS via the Last Name field of a member.
1Restaurant Management System Project
1Restaurant Management System
Jun 17, 2026
Oct 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Sourcecodester Restaurant Management System 1.0 allows XSS via the "send a message" screen.
1Typestack Class Validator Project
1Typestack Class Validator
Jun 17, 2026
Oct 24, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues paramet...Show more
In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this option is not documented and thus most developers configure input validation in the vulnerable default manner. With this vulnerability, attackers can launch SQL Injection or XSS attacks by injecting arbitrary malicious input. NOTE: a software maintainer agrees with the "is not documented" finding but suggests that much of the responsibility for the risk lies in a different product.Show less
1Horde
1Groupware
Jun 17, 2026
Oct 24, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags co...Show more
Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated by the treanBookmarkTags parameter to the trean/ URI on a webmail server. NOTE: treanBookmarkTags could, for example, be a stored XSS payload.Show less
1Horde
1Groupware
Jun 17, 2026
Oct 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.php?form=remove_f&user_name= or admin/config/diff.php?app= URI.
1Dormsystem Project
1Dormsystem
Jun 17, 2026
Oct 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
tonyy dormsystem through 1.3 allows DOM XSS.
1Ibm
9Maximo Asset Management
Maximo For AviationMaximo For Life Sciences+6 more
Jun 17, 2026
Oct 24, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred...Show more
IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164070.Show less
1Ibm
1Cloud Orchestrator
Jun 17, 2026
Oct 24, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the We...Show more
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 163656.Show less
1Thycotic
1Secret Server
Jun 17, 2026
Oct 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 2 of 2).
1Thycotic
1Secret Server
Jun 17, 2026
Oct 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 1 of 2).
1Ant.design
1Ant Design Pro
Jun 17, 2026
Oct 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter affects the authorization component, leading to execution of JavaScript code in the login after-action script.
1Hexo Admin Project
1Hexo Admin
Jun 17, 2026
Oct 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Oct 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to 4.5.7, the file app\extensions\extension_imports.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.
2Awesomemotive
Easydigitaldownloads
2Easy Digital Downloads
Recount Earnings
Feb 7, 2025
Oct 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Easy Digital Downloads (EDD) Recount Earnings extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, ha...Show more
The Easy Digital Downloads (EDD) Recount Earnings extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.Show less
2Awesomemotive
Easydigitaldownloads
2Easy Digital Downloads
Recommended Products
Feb 7, 2025
Oct 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Easy Digital Downloads (EDD) Recommended Products extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7...Show more
The Easy Digital Downloads (EDD) Recommended Products extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.Show less
2Awesomemotive
Easydigitaldownloads
2Easy Digital Downloads
Qr Code
Feb 7, 2025
Oct 23, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Easy Digital Downloads (EDD) QR Code extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS bec...Show more
The Easy Digital Downloads (EDD) QR Code extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.Show less