CWE-79
46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,318)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Adobe 1Experience Manager Forms Jun 17, 2026 Oct 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLoofah+1 moreJun 17, 2026 Oct 22, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. |
1Exquisite Ultimate Newspaper Project 1Exquisite Ultimate Newspaper Nov 21, 2024 Oct 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js. |
1Syndication Links Project 1Syndication Links Nov 21, 2024 Oct 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier. |
1Indieweb Post Kinds Project 1Indieweb Post Kinds Nov 21, 2024 Oct 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The indieweb-post-kinds plugin before 1.3.1.1 for WordPress has XSS via the genericons/example.html anchor identifier. |
1Nlb Creationst 1My Wish List Nov 21, 2024 Oct 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The my-wish-list plugin before 1.4.2 for WordPress has multiple XSS issues. |
totemodata 3.0.0_b936 has XSS via a folder name. |
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line. |
In FusionPBX up to 4.5.7, the file app\contacts\contact_times.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS. |
In FusionPBX up to 4.5.7, the file app\fifo_list\fifo_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS. |
In FusionPBX up to 4.5.7, the file app\sip_status\sip_status.php uses an unsanitized "savemsg" variable coming from the URL, which is reflected in HTML, leading to XSS. |
An issue was discovered in FusionPBX up to 4.5.7. In the file app\conference_controls\conference_control_details.php, an unsanitized id variable coming from the URL is reflected in HTML on 2 occasions, leading to XSS. |
2Freepbx Sangoma2Freepbx ManagerJun 17, 2026 Oct 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager module form (html\admin\modules\manager\views\form.php), an unsanitized managerdisplay variable comi...Show more |
2Freepbx Sangoma2Contactmanager FreepbxJun 17, 2026 Oct 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for FreePBX 14.0.10.3. In the Contactmanager class (html\admin\modules\contactmanager\Contactmanager.class...Show more |
On the RICOH MP 501 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn and KeyDisplay parameter to /web/entry/en/address/adrsSetUserWizard.cgi. |
In FusionPBX up to v4.5.7, the file app\edit\filedelete.php uses an unsanitized "file" variable coming from the URL, which is reflected in HTML, leading to XSS. |
In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS. |
In FusionPBX up to v4.5.7, the file app\basic_operator_panel\resources\content.php uses an unsanitized "eavesdrop_dest" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS. |
In FusionPBX up to v4.5.7, the file app\contacts\contact_import.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS. |
In FusionPBX up to v4.5.7, the file app\recordings\recording_play.php uses an unsanitized "filename" variable coming from the URL, which is base64 decoded and reflected in HTML, leading to XSS. |