← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kirona
1Dynamic Resource Scheduling
Jun 17, 2026
Oct 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script via the /osm/report/ password param...Show more
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script via the /osm/report/ password parameter.Show less
1Icewarp
1Webclient
Nov 21, 2024
Oct 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/ with the parameter password is non-persistent in 10.2.0.
1Icewarp
1Webclient
Nov 21, 2024
Oct 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][uid] is non-persistent in 10.1.3 and 10.2.0.
1Icewarp
1Webclient
Nov 21, 2024
Oct 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][action] is non-persistent in 10.1.3 and 10.2.0.
1Icewarp
1Webclient
Nov 21, 2024
Oct 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][controller] is non-persistent in 10.1.3 and 10.2.0.
1Icewarp
1Webclient
Nov 21, 2024
Oct 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: admin/login.html with the parameter username is persistent in 10.2.0.
1Craftcms
1Craft Cms
Jun 17, 2026
Oct 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
1Laravel Bjyblog Project
1Laravel Bjyblog
Jun 17, 2026
Oct 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
laravel-bjyblog 6.1.1 has XSS via a crafted URL.
1Jnoj
1Jiangnan Online Judge
Jun 17, 2026
Oct 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[sample_input] parameter to web/admin/problem/create or web/polygon/problem/update.
1Jnoj
1Jiangnan Online Judge
Jun 17, 2026
Oct 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[description] parameter to web/admin/problem/create or web/polygon/problem/update.
1Jnoj
1Jiangnan Online Judge
Jun 17, 2026
Oct 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[title] parameter to web/polygon/problem/create or web/polygon/problem/update or web/admin/problem/create.
1B3log
1Symphony
Jun 17, 2026
Oct 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header.
1No Margin For Error
1Prettyphoto
Nov 21, 2024
Oct 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
prettyPhoto before 3.1.6 has js/jquery.prettyPhoto.js XSS.
1Monitorbacklinks
1Incoming Links
Nov 21, 2024
Oct 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The incoming-links plugin before 0.9.10b for WordPress has referrers.php XSS via the Referer HTTP header.
1Cybercraftit
1Content Grabber
Nov 21, 2024
Oct 10, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The content-grabber plugin 1.0 for WordPress has XSS via obj_field_name or obj_field_id.
1K 78
1Broken Link Manager
Nov 21, 2024
Oct 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The broken-link-manager plugin 0.4.5 for WordPress has XSS via the page parameter in a delURL action.
1Seo Searchterms Tagging 2 Project
1Seo Searchterms Tagging 2
Nov 21, 2024
Oct 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The searchterms-tagging-2 plugin through 1.535 for WordPress has XSS via the wp-admin/options-general.php count parameter.
1Microsoft
1Dynamics 365
Jun 17, 2026
Oct 10, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cr...Show more
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'.Show less
1Microsoft
2Sharepoint Enterprise Server
Sharepoint Foundation
Jun 17, 2026
Oct 10, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privileg...Show more
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1330.Show less
1Microsoft
2Sharepoint Enterprise Server
Sharepoint Foundation
Jun 17, 2026
Oct 10, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'.