← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface), which uses an unsanitized "param" variable constructed partially from the URL args and reflected...Show more
In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface), which uses an unsanitized "param" variable constructed partially from the URL args and reflected in HTML, leading to XSS.Show less
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to v4.5.7, the file app\access_controls\access_control_nodes.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to v4.5.7, the file app\conference_profiles\conference_profile_params.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to v4.5.7, the file app\contacts\contact_urls.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.
1Fusionpbx
1Fusionpbx
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In FusionPBX up to v4.5.7, the file app\devices\device_settings.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.
1Open Emr
1Openemr
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter.
1Open Emr
1Openemr
Jun 17, 2026
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 allows a remote attacker to execute arbitrary code in the context of a user's session via the pid parameter.
1Verodin
1Director
Jun 17, 2026
Oct 21, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
There is Stored XSS in Verodin Director 3.5.3.0 and earlier via input fields of certain tooltips, and on the Tags, Sequences, and Actors pages.
1Etherpad
1Etherpad
Jun 17, 2026
Oct 19, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
1Hcltech
1Traveler
Jun 17, 2026
Oct 18, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem...Show more
HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name returns an error message that includes the entered file name. If the file name is not escaped in the returned error page, it could expose a cross-site scripting (XSS) vulnerability.Show less
1Managewp
1Broken Link Checker
Jun 17, 2026
Oct 18, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A reflected XSS vulnerability was found in includes/admin/table-printer.php in the broken-link-checker (aka Broken Link Checker) plugin 1.11.8 for WordPress. This allows unauthorized users to inject client-side JavaScrip...Show more
A reflected XSS vulnerability was found in includes/admin/table-printer.php in the broken-link-checker (aka Broken Link Checker) plugin 1.11.8 for WordPress. This allows unauthorized users to inject client-side JavaScript into an admin-only WordPress page via the wp-admin/tools.php?page=view-broken-links s_filter parameter in a search action.Show less
1Adobe
2Acrobat Dc
Acrobat Reader Dc
Jun 17, 2026
Oct 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a cross-site scripting vulnerability...Show more
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a cross-site scripting vulnerability. Successful exploitation could lead to information disclosure.Show less
1Wikidsystems
12fa Enterprise Server
Jun 17, 2026
Oct 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/adm_usrs.jsp. The usr param...Show more
A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/adm_usrs.jsp. The usr parameter is vulnerable: the reflected cross-site scripting occurs immediately after the user is created. The malicious script is stored and will be executed whenever /WiKIDAdmin/adm_usrs.jsp is visited.Show less
1Wikidsystems
1Two Factor Authentication Enterprise Server
Jun 17, 2026
Oct 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/groups.jsp. The groupName p...Show more
A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/groups.jsp. The groupName parameter is vulnerable: the reflected cross-site scripting occurs immediately after the group is created. The malicious script is stored and will be executed again whenever /WiKIDAdmin/groups.jsp is visited.Show less
1Wikidsystems
1Two Factor Authentication Enterprise Server
Jun 17, 2026
Oct 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML that is triggered when Logs.jsp is visited. The rendere...Show more
Multiple cross-site scripting (XSS) vulnerabilities in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML that is triggered when Logs.jsp is visited. The rendered_message column is retrieved and displayed, unsanitized, on Logs.jsp. A remote attack can populate the rendered_message column with malicious values via: (1) H parameter to /wikid/servlet/com.wikidsystems.server.GetDomainHash (2) S parameter to: - /wikid/DomainData - /wikid/PreRegisterLookup - /wikid/PreRegister - /wikid/InitDevice - /wikid/servlet/InitDevice2S - /wikid/servlet/InitDevice3S - /servlet/com.wikidsystems.server.InitDevice2S - /servlet/com.wikidsystems.server.InitDevice3S - /servlet/com.wikidsystems.server.InitDevice4S - /wikid/servlet/com.wikidsystems.server.InitDevice4AES - /wikid/servlet/com.wikidsystems.server.InitDevice5AES (3) a parameter to: - /wikid/PreRegisterLookup - /wikid/InitDevice - /wikid/servlet/InitDevice2S - /wikid/servlet/InitDevice3S - /servlet/com.wikidsystems.server.InitDevice2S - /servlet/com.wikidsystems.server.InitDevice3S - /servlet/com.wikidsystems.server.InitDevice4S - /wikid/servlet/com.wikidsystems.server.InitDevice4AES - /wikid/servlet/com.wikidsystems.server.InitDevice5AES.Show less
1Wikidsystems
1Two Factor Authentication Enterprise Server
Jun 17, 2026
Oct 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allows remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/userPreregistration.jsp. T...Show more
A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allows remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/userPreregistration.jsp. The preRegistrationData parameter is vulnerable: a reflected cross-site scripting occurs immediately after a .csv file is uploaded. The malicious script is stored and can be executed again when the List Pre-Registration functionality is used.Show less
1Nchsoftware
1Express Accounts Accounting
Jun 17, 2026
Oct 17, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Sales Ord...Show more
In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Sales Orders/Items/Customers/Quotes fields parameter to inject arbitrary JavaScript.Show less
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Oct 17, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
2Debian
Wordpress
2Debian Linux
Wordpress
Jun 17, 2026
Oct 17, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
1Comtech
1H8 Heights Remote Gateway Firmware
Jun 17, 2026
Oct 17, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Comtech H8 Heights Remote Gateway 2.5.1 devices allow XSS and HTML injection via the Site Name (aka SiteName) field.