← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Limesurvey
1Limesurvey
Jun 17, 2026
Oct 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in admin/translate/translateheader_view.php in LimeSurvey 3.19.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the tolang parameter, as demonstr...Show more
A cross-site scripting (XSS) vulnerability in admin/translate/translateheader_view.php in LimeSurvey 3.19.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the tolang parameter, as demonstrated by the index.php/admin/translate/sa/index/surveyid/336819/lang/ PATH_INFO.Show less
4Debian
FedoraprojectPivotal Software+1 more
5Debian Linux
FedoraOpenstack+2 more
Jun 17, 2026
Oct 16, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits p...Show more
Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack that would gain access to virtual hosts and policy management information.Show less
1Pixelite
1Events Manager
Jun 17, 2026
Oct 16, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and...Show more
The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin.Show less
1Eu Cookie Law Project
1Eu Cookie Law
Jun 17, 2026
Oct 16, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to improper encoding of several configuration options in the admin area and the displayed cookie consent me...Show more
The eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to improper encoding of several configuration options in the admin area and the displayed cookie consent message. This affects Font Color, Background Color, and the Disable Cookie text. An attacker with high privileges can attack other users.Show less
1Managewp
1Broken Link Checker
Jun 17, 2026
Oct 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The broken-link-checker plugin through 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS due to improper encoding and insertion of an HTTP GET parameter into HTML. The filter function on the...Show more
The broken-link-checker plugin through 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS due to improper encoding and insertion of an HTTP GET parameter into HTML. The filter function on the page listing all detected broken links can be exploited by providing an XSS payload in the s_filter GET parameter in a filter_id=search request. NOTE: this is an end-of-life product.Show less
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Oct 16, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Oct 16, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen.
1Semperplugins
1All In One Seo Pack
Jun 17, 2026
Oct 16, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding of the SEO-specific description for posts provided by the plugin via unsafe placeh...Show more
The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding of the SEO-specific description for posts provided by the plugin via unsafe placeholder replacement.Show less
1Rambox
1Rambox
Jun 17, 2026
Oct 16, 2019
N/A· v4
9.0 CRITICAL· v3
8.5 HIGH· v2
There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed...Show more
There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for Node.js and Electron, such as an exec of OS commands within the onerror attribute of an IMG element.Show less
1Netgear
1Jnr1010 Firmware
Nov 21, 2024
Oct 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
NETGEAR JNR1010 devices before 1.0.0.32 allow webproc?getpage= XSS.
1Mindpalette
1Natemail
Jun 17, 2026
Oct 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A reflected Cross-Site Scripting (XSS) vulnerability in MindPalette NateMail 3.0.15 allows an attacker to execute remote JavaScript in a victim's browser via a specially crafted POST request. The application will reflect...Show more
A reflected Cross-Site Scripting (XSS) vulnerability in MindPalette NateMail 3.0.15 allows an attacker to execute remote JavaScript in a victim's browser via a specially crafted POST request. The application will reflect the recipient value if it is not in the NateMail recipient array. Note that this array is keyed via integers by default, so any string input will be invalid.Show less
2Debian
Haml
2Debian Linux
Haml
Nov 21, 2024
Oct 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate...Show more
In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially executing code.Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Oct 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.
1Nchsoftware
1Express Invoice
Jun 17, 2026
Oct 14, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Customers fields parame...Show more
In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Customers fields parameter to inject arbitrary JavaScript.Show less
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Oct 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OX App Suite 7.10.1 and 7.10.2 allows XSS.
1Sonarsource
1Sonarqube
Jun 17, 2026
Oct 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SonarSource SonarQube before 7.8 has XSS in project links on account/projects.
1Scadabr
1Scadabr
Jun 17, 2026
Oct 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attacker to inject arbitrary web script or HTML via the username or password parameter.
1Gilacms
1Gila Cms
Jun 17, 2026
Oct 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Gila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a related issue to CVE-2019-9647.
1Hotarucms
1Hotarucms
Jun 17, 2026
Oct 12, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A stored XSS vulnerability was discovered in Hotaru CMS v1.7.2 via the admin_index.php?page=settings SITE NAME field (aka SITE_NAME), a related issue to CVE-2011-4709.1.
1Genesys
1Eservices Chat
Jun 17, 2026
Oct 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Genesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, ClientNickNameColor, Email, email, or email_address parameter).