CWE-79
46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,318)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A cross-site scripting (XSS) vulnerability in admin/translate/translateheader_view.php in LimeSurvey 3.19.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the tolang parameter, as demonstr...Show more |
4Debian FedoraprojectPivotal Software+1 more5Debian Linux FedoraOpenstack+2 moreJun 17, 2026 Oct 16, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits p...Show more |
The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and...Show more |
1Eu Cookie Law Project 1Eu Cookie Law Jun 17, 2026 Oct 16, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to improper encoding of several configuration options in the admin area and the displayed cookie consent me...Show more |
1Managewp 1Broken Link Checker Jun 17, 2026 Oct 16, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The broken-link-checker plugin through 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS due to improper encoding and insertion of an HTTP GET parameter into HTML. The filter function on the...Show more |
1Cmsmadesimple 1Cms Made Simple Jun 17, 2026 Oct 16, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" screen. |
1Cmsmadesimple 1Cms Made Simple Jun 17, 2026 Oct 16, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload images" screen. |
1Semperplugins 1All In One Seo Pack Jun 17, 2026 Oct 16, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to improper encoding of the SEO-specific description for posts provided by the plugin via unsafe placeh...Show more |
There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed...Show more |
NETGEAR JNR1010 devices before 1.0.0.32 allow webproc?getpage= XSS. |
A reflected Cross-Site Scripting (XSS) vulnerability in MindPalette NateMail 3.0.15 allows an attacker to execute remote JavaScript in a victim's browser via a specially crafted POST request. The application will reflect...Show more |
2Debian Haml2Debian Linux HamlNov 21, 2024 Oct 15, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate...Show more |
There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php. |
In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input field. An authenticated unprivileged user can add/modify the Invoices/Items/Customers fields parame...Show more |
1Open Xchange 1Open Xchange Appsuite Jun 17, 2026 Oct 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 OX App Suite 7.10.1 and 7.10.2 allows XSS. |
SonarSource SonarQube before 7.8 has XSS in project links on account/projects. |
A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attacker to inject arbitrary web script or HTML via the username or password parameter. |
Gila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a related issue to CVE-2019-9647. |
A stored XSS vulnerability was discovered in Hotaru CMS v1.7.2 via the admin_index.php?page=settings SITE NAME field (aka SITE_NAME), a related issue to CVE-2011-4709.1. |
Genesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, ClientNickNameColor, Email, email, or email_address parameter). |