← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
1Experience Manager Forms
Jun 17, 2026
Oct 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraLoofah+1 more
Jun 17, 2026
Oct 22, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
1Exquisite Ultimate Newspaper Project
1Exquisite Ultimate Newspaper
Nov 21, 2024
Oct 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js.
1Syndication Links Project
1Syndication Links
Nov 21, 2024
Oct 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier.
1Indieweb Post Kinds Project
1Indieweb Post Kinds
Nov 21, 2024
Oct 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The indieweb-post-kinds plugin before 1.3.1.1 for WordPress has XSS via the genericons/example.html anchor identifier.
1Nlb Creationst
1My Wish List
Nov 21, 2024
Oct 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The my-wish-list plugin before 1.4.2 for WordPress has multiple XSS issues.
1Totemo
1Totemodata
Jun 17, 2026
Oct 22, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
totemodata 3.0.0_b936 has XSS via a folder name.
1Rocketchat
1Rocket.chat
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to 4.5.7, the file app\contacts\contact_times.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to 4.5.7, the file app\fifo_list\fifo_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to 4.5.7, the file app\sip_status\sip_status.php uses an unsanitized "savemsg" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in FusionPBX up to 4.5.7. In the file app\conference_controls\conference_control_details.php, an unsanitized id variable coming from the URL is reflected in HTML on 2 occasions, leading to XSS.
2Freepbx
Sangoma
2Freepbx
Manager
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager module form (html\admin\modules\manager\views\form.php), an unsanitized managerdisplay variable comi...Show more
An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager module form (html\admin\modules\manager\views\form.php), an unsanitized managerdisplay variable coming from the URL is reflected in HTML, leading to XSS. It can be requested via GET request to /config.php?type=tool&display=manager.Show less
2Freepbx
Sangoma
2Contactmanager
Freepbx
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for FreePBX 14.0.10.3. In the Contactmanager class (html\admin\modules\contactmanager\Contactmanager.class...Show more
An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for FreePBX 14.0.10.3. In the Contactmanager class (html\admin\modules\contactmanager\Contactmanager.class.php), an unsanitized group variable coming from the URL is reflected in HTML on 2 occasions, leading to XSS. It can be requested via a GET request to /admin/ajax.php?module=contactmanager.Show less
1Ricoh
1Mp 501 Firmware
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On the RICOH MP 501 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn and KeyDisplay parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to v4.5.7, the file app\edit\filedelete.php uses an unsanitized "file" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to v4.5.7, the file app\basic_operator_panel\resources\content.php uses an unsanitized "eavesdrop_dest" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to v4.5.7, the file app\contacts\contact_import.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to v4.5.7, the file app\recordings\recording_play.php uses an unsanitized "filename" variable coming from the URL, which is base64 decoded and reflected in HTML, leading to XSS.