← Back
CWE-79

46,318 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (46,318)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Sharepoint Enterprise Server
Jun 17, 2026
Oct 10, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnera...Show more
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.Show less
1Lavalite
1Lavalite
Jun 17, 2026
Oct 10, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen.
1Laravel Admin
1Laravel Admin
Jun 17, 2026
Oct 10, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
z-song laravel-admin 1.7.3 has XSS via the Slug or Name on the Roles screen, because of mishandling on the "Operation log" screen.
1Fastadmin
1Fastadmin
Jun 17, 2026
Oct 10, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultant XSS via the row[name] parameter.
1Eyoucms
1Eyoucms
Jun 17, 2026
Oct 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter.
1Realbigplugins
1Client Dash
Jun 17, 2026
Oct 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The client-dash (aka Client Dash) plugin 2.1.4 for WordPress allows XSS.
1Lqd
1Liquid Speech Balloon
Jun 17, 2026
Oct 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The liquid-speech-balloon (aka LIQUID SPEECH BALLOON) plugin before 1.0.7 for WordPress allows XSS with Internet Explorer.
1Redmine
1Redmine
Jun 17, 2026
Oct 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
1Pbootcms
1Pbootcms
Jun 17, 2026
Oct 10, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs.
1Juniper
1Junos
Jun 17, 2026
Oct 9, 2019
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
A persistent Cross-Site Scripting (XSS) vulnerability in Junos OS J-Web interface may allow remote unauthenticated attackers to perform administrative actions on the Junos device. Successful exploitation requires a Junos...Show more
A persistent Cross-Site Scripting (XSS) vulnerability in Junos OS J-Web interface may allow remote unauthenticated attackers to perform administrative actions on the Junos device. Successful exploitation requires a Junos administrator to first perform certain diagnostic actions on J-Web. This issue affects: Juniper Networks Junos OS 12.1X46 versions prior to 12.1X46-D86; 12.3 versions prior to 12.3R12-S13; 12.3X48 versions prior to 12.3X48-D80; 14.1X53 versions prior to 14.1X53-D51; 15.1 versions prior to 15.1F6-S13, 15.1R7-S4; 15.1X49 versions prior to 15.1X49-D171, 15.1X49-D180; 15.1X53 versions prior to 15.1X53-D497, 15.1X53-D69; 16.1 versions prior to 16.1R7-S5; 16.2 versions prior to 16.2R2-S9; 17.1 versions prior to 17.1R3; 17.2 versions prior to 17.2R1-S8, 17.2R2-S7, 17.2R3-S1; 17.3 versions prior to 17.3R3-S6; 17.4 versions prior to 17.4R1-S7, 17.4R2-S4, 17.4R3; 18.1 versions prior to 18.1R3-S5; 18.2 versions prior to 18.2R1-S5, 18.2R2-S3, 18.2R3; 18.3 versions prior to 18.3R1-S3, 18.3R2, 18.3R3; 18.4 versions prior to 18.4R1-S2, 18.4R2.Show less
1Openproject
1Openproject
Jun 17, 2026
Oct 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS vulnerability in project list in OpenProject before 9.0.4 and 10.x before 10.0.2 allows remote attackers to inject arbitrary web script or HTML via the sortBy parameter because error messages are mishandled.
1Eleopard
1Animate It!
Jun 17, 2026
Oct 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The animate-it plugin before 2.3.5 for WordPress has XSS.
1Eleopard
1Animate It!
Jun 17, 2026
Oct 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The animate-it plugin before 2.3.4 for WordPress has XSS.
1Cpanel
1Cpanel
Jun 17, 2026
Oct 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).
1Cpanel
1Cpanel
Jun 17, 2026
Oct 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527).
1Cpanel
1Cpanel
Jun 17, 2026
Oct 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526).
1Cpanel
1Cpanel
Jun 17, 2026
Oct 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524).
1Cpanel
1Cpanel
Jun 17, 2026
Oct 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521).
1Tibco
1Master Data Management
Jun 17, 2026
Oct 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The MDM server component of TIBCO Software Inc's TIBCO MDM contains multiple vulnerabilities that theoretically allow an authenticated user with specific roles to perform cross-site scripting (XSS) attacks. This issue af...Show more
The MDM server component of TIBCO Software Inc's TIBCO MDM contains multiple vulnerabilities that theoretically allow an authenticated user with specific roles to perform cross-site scripting (XSS) attacks. This issue affects TIBCO Software Inc.'s TIBCO MDM version 9.0.1 and prior versions; version 9.1.0.Show less
1S Cms
1S Cms
Jun 17, 2026
Oct 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
S-CMS v1.5 has XSS in tpl.php via the member/member_login.php from parameter.