CWE-79
46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,318)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface), which uses an unsanitized "param" variable constructed partially from the URL args and reflected...Show more |
In FusionPBX up to v4.5.7, the file app\access_controls\access_control_nodes.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS. |
In FusionPBX up to v4.5.7, the file app\conference_profiles\conference_profile_params.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS. |
In FusionPBX up to v4.5.7, the file app\contacts\contact_urls.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS. |
In FusionPBX up to v4.5.7, the file app\devices\device_settings.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS. |
Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter. |
Reflected XSS in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 allows a remote attacker to execute arbitrary code in the context of a user's session via the pid parameter. |
There is Stored XSS in Verodin Director 3.5.3.0 and earlier via input fields of certain tooltips, and on the Tags, Sequences, and Actors pages. |
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer. |
HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem...Show more |
A reflected XSS vulnerability was found in includes/admin/table-printer.php in the broken-link-checker (aka Broken Link Checker) plugin 1.11.8 for WordPress. This allows unauthorized users to inject client-side JavaScrip...Show more |
1Adobe 2Acrobat Dc Acrobat Reader DcJun 17, 2026 Oct 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a cross-site scripting vulnerability...Show more |
1Wikidsystems 12fa Enterprise Server Jun 17, 2026 Oct 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/adm_usrs.jsp. The usr param...Show more |
1Wikidsystems 1Two Factor Authentication Enterprise Server Jun 17, 2026 Oct 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/groups.jsp. The groupName p...Show more |
1Wikidsystems 1Two Factor Authentication Enterprise Server Jun 17, 2026 Oct 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML that is triggered when Logs.jsp is visited. The rendere...Show more |
1Wikidsystems 1Two Factor Authentication Enterprise Server Jun 17, 2026 Oct 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allows remote attackers to inject arbitrary web script or HTML via /WiKIDAdmin/userPreregistration.jsp. T...Show more |
1Nchsoftware 1Express Accounts Accounting Jun 17, 2026 Oct 17, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Sales Ord...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements. |
1Comtech 1H8 Heights Remote Gateway Firmware Jun 17, 2026 Oct 17, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Comtech H8 Heights Remote Gateway 2.5.1 devices allow XSS and HTML injection via the Site Name (aka SiteName) field. |