CWE-79
46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVEs (46,318)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 1Sharepoint Enterprise Server Jun 17, 2026 Oct 10, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnera...Show more |
LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen. |
z-song laravel-admin 1.7.3 has XSS via the Slug or Name on the Roles screen, because of mishandling on the "Operation log" screen. |
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultant XSS via the row[name] parameter. |
EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter. |
1Realbigplugins 1Client Dash Jun 17, 2026 Oct 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The client-dash (aka Client Dash) plugin 2.1.4 for WordPress allows XSS. |
The liquid-speech-balloon (aka LIQUID SPEECH BALLOON) plugin before 1.0.7 for WordPress allows XSS with Internet Explorer. |
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors. |
PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs. |
A persistent Cross-Site Scripting (XSS) vulnerability in Junos OS J-Web interface may allow remote unauthenticated attackers to perform administrative actions on the Junos device. Successful exploitation requires a Junos...Show more |
An XSS vulnerability in project list in OpenProject before 9.0.4 and 10.x before 10.0.2 allows remote attackers to inject arbitrary web script or HTML via the sortBy parameter because error messages are mishandled. |
The animate-it plugin before 2.3.5 for WordPress has XSS. |
The animate-it plugin before 2.3.4 for WordPress has XSS. |
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528). |
cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527). |
cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526). |
cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524). |
cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521). |
The MDM server component of TIBCO Software Inc's TIBCO MDM contains multiple vulnerabilities that theoretically allow an authenticated user with specific roles to perform cross-site scripting (XSS) attacks. This issue af...Show more |
S-CMS v1.5 has XSS in tpl.php via the member/member_login.php from parameter. |