CWE-79
46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,318)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Kirona 1Dynamic Resource Scheduling Jun 17, 2026 Oct 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script via the /osm/report/ password param...Show more |
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/ with the parameter password is non-persistent in 10.2.0. |
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][uid] is non-persistent in 10.1.3 and 10.2.0. |
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][action] is non-persistent in 10.1.3 and 10.2.0. |
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][controller] is non-persistent in 10.1.3 and 10.2.0. |
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: admin/login.html with the parameter username is persistent in 10.2.0. |
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion. |
1Laravel Bjyblog Project 1Laravel Bjyblog Jun 17, 2026 Oct 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 laravel-bjyblog 6.1.1 has XSS via a crafted URL. |
1Jnoj 1Jiangnan Online Judge Jun 17, 2026 Oct 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[sample_input] parameter to web/admin/problem/create or web/polygon/problem/update. |
1Jnoj 1Jiangnan Online Judge Jun 17, 2026 Oct 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[description] parameter to web/admin/problem/create or web/polygon/problem/update. |
1Jnoj 1Jiangnan Online Judge Jun 17, 2026 Oct 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[title] parameter to web/polygon/problem/create or web/polygon/problem/update or web/admin/problem/create. |
b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header. |
1No Margin For Error 1Prettyphoto Nov 21, 2024 Oct 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 prettyPhoto before 3.1.6 has js/jquery.prettyPhoto.js XSS. |
1Monitorbacklinks 1Incoming Links Nov 21, 2024 Oct 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The incoming-links plugin before 0.9.10b for WordPress has referrers.php XSS via the Referer HTTP header. |
The content-grabber plugin 1.0 for WordPress has XSS via obj_field_name or obj_field_id. |
The broken-link-manager plugin 0.4.5 for WordPress has XSS via the page parameter in a delURL action. |
1Seo Searchterms Tagging 2 Project 1Seo Searchterms Tagging 2 Nov 21, 2024 Oct 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The searchterms-tagging-2 plugin through 1.535 for WordPress has XSS via the wp-admin/options-general.php count parameter. |
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cr...Show more |
1Microsoft 2Sharepoint Enterprise Server Sharepoint FoundationJun 17, 2026 Oct 10, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privileg...Show more |
1Microsoft 2Sharepoint Enterprise Server Sharepoint FoundationJun 17, 2026 Oct 10, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. |